Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Esbuild's XSS Bug that Survived 5 Billion Downloads and Bypassed HTML Sanitization

Summary

How a low-severity XSS flag in esbuild's dev server became real: a folder name containing a double quote escaped the escapeForHTML function, enabling script execution; the fix was one line.
Published
Collected

original ↗

Related coverage

back