You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I managed to find machine with macOS 10.15.4, reproduce and fix this issue 🙂
Fix applied in f8c75d8 - add XML escaping for file name.
Released as 1.6.2.
Inspired by https://twitter.com/_r3ggi/status/1265629984753844225
I did a quick check with
<img src=1 onerror=document.documentElement.textContent=window.location>.ipa
and looks like the XSS works:The text was updated successfully, but these errors were encountered: