Collected research
From Markdown to RCE in Atom
The Atom editor's Markdown preview rendered arbitrary HTML behind a weak attribute-stripping sanitiser, so an iframe could load a bundled local HTML file that passed the URL query string to eval. Because Electron runs that file under the same file:// origin, the chain reaches window.top.require('child_process') and executes local code from a package README.
Record
- Published by
- statuscode.ch
- Topic
- Server
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of statuscode.ch, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .