Hi maintainers,
I've identified a stored XSS vulnerability in ete4's explorer.py (smartview web server) that allows injection of arbitrary JavaScript via tree names.
Could you either:
Enable GitHub private vulnerability reporting on this repo
Provide a security contact email
I have a full report with PoC ready to share privately.
Thank you.
— Woohyun Choi (@woohyunchoi-kentech) & Sunwoo Lee (@programsurf)
Hi maintainers,
I've identified a stored XSS vulnerability in ete4's explorer.py (smartview web server) that allows injection of arbitrary JavaScript via tree names.
Could you either:
Enable GitHub private vulnerability reporting on this repo
Provide a security contact email
I have a full report with PoC ready to share privately.
Thank you.
— Woohyun Choi (@woohyunchoi-kentech) & Sunwoo Lee (@programsurf)