WhisperX tag archive

#dom-based-xss

This page collects WhisperX intelligence signals tagged #dom-based-xss. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-05-09 23:31:51 · GitHub Issues

1. Homeschool Hero Repository Carries Unpatched DOM-Based XSS in File Upload Component

A CodeQL security scan has flagged a high-severity cross-site scripting vulnerability in the `homeschool-hero` repository managed by user `x3nc0n`. The flaw, classified as `js/xss-through-dom`, resides in `frontend/src/components/features/FileUpload.tsx` at line 273. The scanner identified that DOM text is being reinte...

The Lab · 2026-05-11 08:10:37 · GitHub Issues

2. CodeQL Flags Unpatched DOM-Based XSS in Homeschool Hero FileUpload Component; Venkman Named Likely Owner

A high-severity cross-site scripting vulnerability has been identified in the frontend infrastructure of homeschool-hero, the open-source project maintained by user x3nc0n. The flaw, detected by GitHub's CodeQL security scanner on May 11, 2026, affects client-side code responsible for handling file uploads and involves...