Simon Willison’s Weblog

Subscribe

Items tagged security, xss in 2017

Filters: Year: 2017 × security × xss × Sorted by date


From Markdown to RCE in Atom (via) Lukas Reschke found a remote code execution vulnerability in the Atom editor by taking advantage of a combination of Markdown’s ability to embed HTML, Atom’s Content-Security-Policy allowing JavaScript from the local filesystem to be executed, and a test suite HTML file hidden away in the Atom application package that executes code passed to it via query string. # 23rd November 2017, 4:13 pm

Types

Years

Months

Tags