Web Hack List

Collected research

XSS Vulnerabilities in Excalidraw Affecting Meta (CVE-2024-32472)

Excalidraw's Web Embed feature builds a sandboxed iframe from a user-supplied link. A gist URL carrying a script tag ran with same-origin access, and after that fix the URL sanitiser still passed double quotes, so an embed from a domain that keeps same-origin escapes the sandbox and runs JavaScript on the Excalidraw host, stealing private boards.

Record

Researcher
El Mehdi Mrhassel
Published by
El Mehdi Mrhassel
Date
Topic
XSS

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of El Mehdi Mrhassel, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .