Collected research
XSS Vulnerabilities in Excalidraw Affecting Meta (CVE-2024-32472)
Excalidraw's Web Embed feature builds a sandboxed iframe from a user-supplied link. A gist URL carrying a script tag ran with same-origin access, and after that fix the URL sanitiser still passed double quotes, so an embed from a domain that keeps same-origin escapes the sandbox and runs JavaScript on the Excalidraw host, stealing private boards.
Record
- Researcher
- El Mehdi Mrhassel
- Published by
- El Mehdi Mrhassel
- Date
- Topic
- XSS
In the archive
Related sources
- Excalidraw CVE-2024-32472 advisory Advisory
Tags
This page is the archive's own catalogue record. The research is the work of El Mehdi Mrhassel, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .