GHSA-gg96-f8wr-p89f
MODERATECVE-2021-32661A malicious internal actor can potentially upload documentation content with malicious scripts by embedding the script within an object element. This may give access to sensitive data when other users visit that same documentation page.
- Affected
- < 0.9.5
- Fixed in
- 0.9.5
- Weakness
- CWE-77
- Published
- 2021-06-04
- Source
- github