Bryan-Roe / semantic-kernel

Integrate cutting-edge LLM technology quickly and easily into your apps
https://bryan-roe.github.io/semantic-kernel/
Apache License 2.0
0 stars 3 forks source link

## If untrusted data (data from HTTP requests, user submitted files, etc.) is included in an setTimeout statement it can allow an attacker to inject their own code. #535

Closed Bryan-Roe closed 2 weeks ago

Bryan-Roe commented 3 months ago

If untrusted data (data from HTTP requests, user submitted files, etc.) is included in an setTimeout statement it can allow an attacker to inject their own code.

Review setTimeout for untrusted data

Show more details

_Originally posted by @github-advanced-security in https://github.com/Bryan-Roe/semantic-kernel/pull/519#discussion_r1703149970_

github-actions[bot] commented 3 weeks ago

Stale issue message