zenorocha / clipboard.js

:scissors: Modern copy to clipboard. No Flash. Just 3kb gzipped :clipboard:
https://clipboardjs.com
MIT License
33.98k stars 3.98k forks source link

Client potential XSS - feedback needed #871

Closed DanielRuf closed 2 months ago

DanielRuf commented 8 months ago

Please check and provide feedback, because so far I can not verify if there is really an issue / a vulnerability.

grafik

obetomuniz commented 2 months ago

@DanielRuf can you check if it still appears when using the latest version of the library? Also, can you please provide a reproducible environment to help me check this report?

In any case, from what I understood, it seems a data sanitization issue, which is not a responsibility of clipboard.js from my perspective at first level, but with additional information, I can go deep into the investigation of your report, and if we find a related vulnerability, we can propose a solution to mitigate.

For now, closing, since it is not using the latest version of the library. Feel free to re-open it if you reproduce it using the latest version.