1. Homeschool Hero Repository Carries Unpatched DOM-Based XSS in File Upload Component
A CodeQL security scan has flagged a high-severity cross-site scripting vulnerability in the `homeschool-hero` repository managed by user `x3nc0n`. The flaw, classified as `js/xss-through-dom`, resides in `frontend/src/components/features/FileUpload.tsx` at line 273. The scanner identified that DOM text is being reinte...