WhisperX tag archive

#Client-Side Security

This page collects WhisperX intelligence signals tagged #Client-Side Security. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-04-14 22:22:49 · GitHub Issues

1. GitHub Project Directory Filter Exposes ReDoS Vulnerability via Unescaped User Input

A critical vulnerability in a GitHub project's directory filter allows user input to be passed directly into a regular expression constructor without escaping, creating a direct path for a Regular Expression Denial of Service (ReDoS) attack. The flaw, located in the `atr/static/js/src/projects-directory.js` file, enabl...

The Lab · 2026-04-21 13:23:10 · GitHub Issues

2. GitHub Security Flaw: Client-Side Guard in TD #525 Exposes All Soft-Deleted Team Documents to Any Authenticated User

A high-severity security vulnerability in a GitHub repository allows any authenticated user to bypass a client-side admin check and directly query the database for all soft-deleted team documents. The flaw, identified in a pre-PR scan for TD #525, stems from a critical mismatch between a frontend JavaScript guard and t...