Skip to content

Error messages are not escaped #351

@lolmaus

Description

@lolmaus

Saw this with a Fastboot error:

image

I think chromespeak Array.map(<anonymous>) is rendered unescaped and treated as containing an HTML tag.

Technically, this is an XSS vulnerability. 😬

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions