GHSA-qmmm-73r2-f8xr
HIGHCVE-2024-34347The Hoppscotch desktop app takes multiple precautions to be secure against arbitrary JavaScript and system command execution. It does not render user-controlled HTML or Markdown, uses Tauri instead of Electron, and sandboxes pre-request scripts with a simple yet secure implementation using web workers.
- Affected
- >= 0.5.0, < 0.8.0
- Fixed in
- 0.8.0
- Weakness
- CWE-77
- Published
- 2024-04-22
- Source
- github