google / blockly-devtools

Tools for Blockly app developers to help build custom blocks.
http://developer.google.com/blockly
Apache License 2.0
60 stars 31 forks source link

Injection vulnerability in prettyPrint JSON #1

Open AnmAtAnm opened 7 years ago

AnmAtAnm commented 7 years ago

See https://github.com/google/blockly/issues/756 and https://blockly-demo.appspot.com/static/demos/blockfactory/index.html#xd6zrv

rachel-fenichel commented 7 years ago

This is the same as the other bug, right? If so, you can just rename the other bug and close this one.

AnmAtAnm commented 7 years ago

The code bases are now separate. It needs to be fixed in both places. One for production now, and the other for the upcoming tool.

rachel-fenichel commented 7 years ago

Gotcha. Thanks.