forked from htmlpreview/htmlpreview.github.com
-
Notifications
You must be signed in to change notification settings - Fork 13
Closed
Labels
documentationImprovements or additions to documentationImprovements or additions to documentation
Description
If a repo script persistently stores sensitive data (as cookie, localStorage
, etc...), then other repos opened by the user will also have access to this data. This isn't inherently a problem of bypassing CORS, so it should be mentioned as an additional risk (both in the README
and the index
)
I haven't tested if this "vulnerability" actually works, but I assume it's likely that it can be easily exploited
Metadata
Metadata
Assignees
Labels
documentationImprovements or additions to documentationImprovements or additions to documentation