Collected research
LEXSS: Bypassing Lexical Parsing Security Controls
HTML sanitisers that re-parse markup can be desynchronised from the browser's own parser. Nesting tags that switch tokenizer state, such as an iframe wrapping a textarea, or entering the MathML namespace, makes the sanitiser treat active content as harmless text, so the final parse executes it. Shown against TinyMCE and Froala.
Record
- Researcher
- @bishopfox
- Published by
- Bishop Fox
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of @bishopfox, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .