AGENTFORCE-VF-01: Visualforce XSS via escape=false
๐จ Critical ยท XSS
Detects Visualforce components with escape="false", which disables auto-escaping and enables XSS.
Detailsโ
| Field | Value |
|---|---|
| Rule ID | AGENTFORCE-VF-01 |
| Severity | Critical |
| Category | XSS |
Remediationโ
Remove escape="false" or ensure the value is strictly sanitized server-side. Prefer apex:outputText with default escaping.