Nuclide Improper Input Validation
Critical severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jul 21, 2023
Description
Published by the National Vulnerability Database
Dec 31, 2018
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jul 21, 2023
Last updated
Jul 21, 2023
The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a malicious URL could be used to render HTML and other content inside of the editor's context, which could potentially be chained to lead to code execution. This issue affected Nuclide prior to v0.290.0.
References