Menu
Login Register
Discussion

Stored XSS leading to tenant takeover

Started by Henry_Lever Aug 4, 2026 11:42 pm 140 views
Posts

10 messages in this thread

H
Henry_Lever Hlever
#1 Aug 4, 2026 11:42 pm

Hello,

I have made a github vulnerability report and sent an email regarding a stored XSS vulnerability I discovered in this project. Please check for emails from [email protected]

Permalink
Phuong avatar
Phuong admin
#2 Aug 5, 2026 9:01 am

Hi Henry
Seen the vulnerability report that pointed out the affected version <= 0.9
Will patch soon this week.

Thank you for detecting this.

Permalink
H
Henry_Lever Hlever
#3 Aug 5, 2026 11:45 pm Edited Aug 5

Hello,

Thank you for working on this. Just to be clear, I put <=0.9 because that is the most recent fully released version. I did not test your 1.0 alpha release but if it handles uploads in the same manner it has the same vulnerability.

Once you publish the vulnerability, could you please request a CVE from Github? It will help me out a lot.

Thanks,

Permalink
H
Henry_Lever Hlever
#6 Aug 12, 2026 4:58 pm

Hello Phuong. Can I help at all with getting a patch for this? I would like to ensure you have any help you need getting this fixed. I would be happy to create a private fork and PR to fix the vulnerability.

Permalink
Phuong avatar
Phuong admin
#9 Aug 14, 2026 4:37 am

Merged and Published. Thank you Henry

Permalink
H
Henry_Lever Hlever
#10 Aug 14, 2026 4:50 am

Happy to be of service! You have been a pleasure to work with, thank you.

Permalink
Reply

Continue the discussion

Sign in to reply.

Guest browsing is open, but posting still requires a standalone forum account.

Login