MYR icon indicating copy to clipboard operation
MYR copied to clipboard

Access to DOM through MYR's IDE presents multiple security vulnerabilities

Open samuel-zuk opened this issue 4 years ago • 0 comments

Currently, user MYR code can access the JS "document" & "window" object, which presents a whole range of opportunities for malicious code execution (as anything can then be injected into the DOM). Steps must be taken to minimize the potential damage that running a JavaScript code sandbox entails.

samuel-zuk avatar Feb 19 '21 20:02 samuel-zuk