bustle / mobiledoc-kit

A toolkit for building WYSIWYG editors with Mobiledoc
https://bustle.github.io/mobiledoc-kit/demo/
MIT License
1.55k stars 150 forks source link

🚨 Potential Cross-site Scripting (XSS) - Reflected (CWE-79) #756

Closed huntr-helper closed 2 years ago

huntr-helper commented 3 years ago

👋 Hello, @bantic, @mixonic, @ZeeJab - a potential critical severity Cross-site Scripting (XSS) - Reflected (CWE-79) vulnerability in your repository has been disclosed to us.

Next Steps

1️⃣ Visit https://huntr.dev/bounties/2-other-bustle/mobiledoc-kit for more advisory information.

2️⃣ Sign-up to validate or speak to the researcher for more assistance.

3️⃣ Propose a patch or outsource it to our community - whoever fixes it gets paid.


Confused or need more help?


This issue was automatically generated by huntr.dev - a bug bounty board for securing open source code.

gpoitch commented 2 years ago

https://github.com/bustle/mobiledoc-kit/blob/master/SECURITY.md