Skip to content

XSS vulnerability via filenames in repository #40

@ecneladis

Description

@ecneladis

XSS is possible via unescaped filename in git repository, e.g. <img src=x onerror=alert(1)>.

image

Repository with POC: https://github.com/ecneladis/xss_github_vector

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions