rom1504 / clip-retrieval

Easily compute clip embeddings and build a clip retrieval system with them
https://rom1504.github.io/clip-retrieval/
MIT License
2.42k stars 213 forks source link

Potential security issue in https://rom1504.github.io/clip-retrieval/ #198

Closed matrs closed 2 years ago

matrs commented 2 years ago

Hey, This just happened to me. I was browsing results in https://rom1504.github.io/clip-retrieval/ , and after a few seconds going though the results, this appeared in my browser: putorfootin.com

I tried a couple of times and always happened (I started searching for something like "adidas sneaker" an then clicking in random images to obtain new results)

rom1504 commented 2 years ago

Hi, that's happens before images are hot linked and some websites are blacklisted by chrome There's no actual risk We could however still use chrome black list to pre filter these domains

On Wed, Oct 26, 2022, 21:26 Jose Luis Maturana @.***> wrote:

Hey, This just happened to me. I was browsing results in https://rom1504.github.io/clip-retrieval/ , and after a few seconds going though the results, this appeared in my browser: [image: putorfootin.com] https://user-images.githubusercontent.com/12502882/198117658-6f4f638c-e697-450a-82a4-9d2cc0dbd504.png

I tried a couple of times and always happened (I started searching for something like "adidas sneaker" an then clicking in random images to obtain new results)

— Reply to this email directly, view it on GitHub https://github.com/rom1504/clip-retrieval/issues/198, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAR437UCCMTIAPNM3PXSMBTWFGAXNANCNFSM6AAAAAARPKHX2Q . You are receiving this because you are subscribed to this thread.Message ID: @.***>

matrs commented 2 years ago

I see, thanks for the clarification :+1: