Skip to content

Conversation

@BorisPolonsky
Copy link

修复多处当用户若输入带有潜在隐患的文本时导致XSS攻击。
案例1
WXWorkCapture_17570646983677
输入文本img//src="x"//onerror="window['al' +'ert'](1)">
修复前(piepeline字段不正常显示,上方弹出alert)
WXWorkCapture_17570655214984

修复后,pipeline字段正常显示
WXWorkCapture_17570744159940

超参搜索页面,notebook页面同理,不再另外附图。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant