Esbuild's XSS Bug that Survived 5 Billion Downloads and Bypassed HTML Sanitization
depthfirst.com | research | #supply-chain | #vulnerability-research | #xss | #javascript | #esbuild | #dev-server | #html-sanitization
Summary
How a low-severity XSS flag in esbuild's dev server became real: a folder name containing a double quote escaped the escapeForHTML function, enabling script execution; the fix was one line.
- Published
- Collected
Skip to content