Web Hack List

Later archive addition

How to bypass CSP nonces with DOM XSS

The article shows how repeatable DOM injection can use CSS attribute selectors to recover a CSP nonce and then execute script with that nonce. It demonstrates the chain with persistent, postMessage-driven, HTTP-inclusion, and location-hash DOM XSS cases.

Record

Researcher
Eduardo Vela and Sebastian Lekies
Published by
sirdarckcat

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Eduardo Vela and Sebastian Lekies, first published at the original source. Preserved copies are kept so the citation survives its host.