What is Nostr?
Evil Jim O’Donnell /
npub1drr…y9wx
2024-12-21 12:49:12

Evil Jim O’Donnell on Nostr: Security question: several months ago I emailed someone about an XSS injection ...

Security question: several months ago I emailed someone about an XSS injection vulnerability in the code that they use to sanitise user-generated content. I got back a ‘we take security seriously’ canned reply, then nothing. The vulnerable library still hasn’t been patched.

What’s the next step, in terms of responsible disclosure? Chase them, or publish the vulnerability publicly?
Author Public Key
npub1drrymhvl20tztfdnxk98rhhsvzdg00cdvvumh6aurwdapjdxzvrsyzy9wx