-
-
Notifications
You must be signed in to change notification settings - Fork 787
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
XSS to code execution vulnerability #109
Comments
Update: within 90 days from 1 of December (time of reporting) I would post a full disclosure on the issue in my blog. You have a good numbers in terms of user base according to the stars you have received in Github for this project, so it would only be fair to the users if a fix was deployed that would prevent the code execution from occuring. Report is still waiting to be sent. |
Props for good disclosure practices. @luin please contact her! |
@silviavali I didn't notice this issue and I'm really sorry for that. The issue have been fixed. Thank you for pointing this out ❤️ . |
Hello,
I would like to report a XSS vulnerability in your application that leads to code execution.
I have a working poc that I dont want to post publicly.
Please contact me at silviavali14@gmail.com
The text was updated successfully, but these errors were encountered: