Collected research
Bypassing CSP via URL Parser Confusions: XSS on Netlify’s Image CDN
Bypassing CSP via URL Parser Confusions : XSS on Netlify’s Image CDN
A stored cross-site scripting finding on Netlify's image CDN endpoint. An upload allowlist that trusted the declared Content-Type let arbitrary HTML be hosted on a whitelisted CDN origin, and the image proxy served it back verbatim; the strict script-src 'none' policy applied to that path was shed by requesting an encoded or doubled-slash variant that the edge did not match but the backend normalised. The resulting script stole an OAuth authorization response.
Record
- Document
- Bypassing CSP via URL Parser Confusions : XSS on Netlify’s Image CDN
- Researcher
- sudi
- Published by
- sudi’s blog
- Date
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of sudi, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .