Steveorevo / node-red-contrib-nbrowser

Provides a virtual web browser (a.k.a. "headless browser") appearing as a node.
34 stars 13 forks source link

security hole #1

Closed francescoagati closed 6 years ago

francescoagati commented 6 years ago

nightmare use electron and in some case can open securty holes on the maschine where node-red run https://github.com/segmentio/nightmare/pull/1234

Steveorevo commented 6 years ago

Correct. It is NOT sandboxed. Suggest adding a warning to the readme (and don't load malicious websites) :)

Steveorevo commented 6 years ago

Documentation updated in f66066d24a7162ffeb5f0752090cc9eec5252c88