Mxss
- SafePaste
A mutation-XSS that looked like a DOMPurify bug but was really a server-side String.replace breakout, plus an iframe and a cookie-scope trick to read a flag cookie scoped to a path …
A mutation-XSS that looked like a DOMPurify bug but was really a server-side String.replace breakout, plus an iframe and a cookie-scope trick to read a flag cookie scoped to a path …