github95
github95 copied to clipboard
potential XSS vulnerability
hey, super cool project!
i think the file viewer is not escaping HTML tags in certain files. i noticed this when it embedded a form into a file i was looking at in one of my own projects, so i dug a little deeper to see if it could be an issue.
repro:
- open repo search
- navigate to swisskyrepo/PayloadsAllTheThings
- go to "files" tab
- view
XSS Injection/README.md
this causes a number of the alerts in that file to be executed: