WhisperX tag archive

#merge-tags

This page collects WhisperX intelligence signals tagged #merge-tags. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-04-17 01:22:43 · GitHub Issues

1. Open-Redirect Risk in Form Handler: Admin-Configured Redirects Can Be Weaponized via User-Controlled Merge Tags

A critical open-redirect vulnerability has been identified in a form submission handler, where admin-configured redirect URLs can be hijacked by end-users. The flaw stems from the system's `renderMergeTags` function, which expands merge tags like `{{fieldId}}` within the `form.settings.redirectUrl` property. This funct...