- cross-posted to:
- cybersecurity@sh.itjust.works
- cross-posted to:
- cybersecurity@sh.itjust.works
Open source React executes malicious code with malformed HTML—no authentication needed.
You must log in or # to comment.
TL;DR:
Arbitrary code execution with no auth required at all.




