MISP <= 2.5.27 - Stored Cross-Site Scripting via Workflow Engine (doT.js Template Injection).
-
Updated
Mar 27, 2026 - Python
MISP <= 2.5.27 - Stored Cross-Site Scripting via Workflow Engine (doT.js Template Injection).
Ultimate DOM Clobbering Cheat Sheet - 100+ exploitation vectors for XSS, CSP bypass, and client-side attacks. Covers browser compatibility, framework evasion, and real-world exploit chains for security researchers and bug bounty hunters
Firefox/Chrome extension to bypass Content Security Policy on JanitorAI. Required for using custom API endpoints with local LLMs.
Add a description, image, and links to the csp-bypass topic page so that developers can more easily learn about it.
To associate your repository with the csp-bypass topic, visit your repo's landing page and select "manage topics."