Skip to content

XSS to RCE - re-opened #26

@silviavali

Description

@silviavali

Hello,

Why would you close an issue, without any information on the decision why you have marked it invalid?
#25

You have a nice blog post about the electorn-markdownify, and I think its is a good application. It would be a pity if you just leave the security issue in there and allow people to keep using it.

Please do check the security checklist for Electron to be aware of the consequences of code execution in Electron applications due to XSS.
https://www.blackhat.com/docs/us-17/thursday/us-17-Carettoni-Electronegativity-A-Study-Of-Electron-Security-wp.pdf

In 90 days I'd disclose information on the issue, so I'm hoping for your collaboration in fixing the issue prior.

Thanks

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions