WhisperX tag archive

#xss-vulnerability

This page collects WhisperX intelligence signals tagged #xss-vulnerability. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-05-07 15:31:51 · GitHub Issues

1. Critical Security Flaw Exposes LLM API Keys Stored in Plain Text via localStorage Vulnerability

A documented security vulnerability in the glowos project leaves LLM API keys exposed in plain text within browser localStorage, creating an immediate attack surface for any cross-site scripting (XSS) exploit. The keys are persisted through the zustand state management library using its persist middleware, which writes...