Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Feels a little overstated if it requires a malicious lua script.

Yes that's bad, but its not critical the way the article implies. For the average website, your average stored XSS is probably more impactful.





Exactly, also requires authentication. How can this be 10/10?



Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: