OSV 1.4.0 · github-reviewed · 修改于 2026-06-20 05:18
发布时间
2026-06-20 05:18
GitHub 审查时间
2026-06-20 05:18
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/06/GHSA-wwf9-7jrc-rv4q/GHSA-wwf9-7jrc-rv4q.json
A Stored Cross-Site Scripting (XSS) issue previously existed in the Text Widget in Board of Outerbase Studio where unsanitized HTML could be rendered using dangerouslySetInnerHTML
<img src=x onerror="alert('XSS Executed\nToken: ' + localStorage.getItem('ob-token'))">
Outerbase Cloud and its backend services were discontinued in 2025.
The current version of Outerbase Studio operates purely as a client-side application, with dashboard data stored locally in the browser.
In the current architecture, the impact is limited to local self-XSS within a user's browser session. The previously described scenarios involving:
are no longer applicable since there are no active backend services or authentication tokens.
The unsafe HTML rendering in the Text Widget has been removed in commit https://github.com/outerbase/studio/commit/b06fb85e5967440278d5a815721b360920566ab9 by eliminating the use of dangerouslySetInnerHTML.