Join GitHub today
GitHub is home to over 40 million developers working together to host and review code, manage projects, and build software together.Sign up
[Fixed] XSS Vulnerability in noVNC #748
An XSS vulnerability was discovered in noVNC in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.
This affects users of vnc_auto.html and vnc.html, as well as any users of include/ui.js.
Thanks to David Wyde of Cisco for reporting the issue.