Disclose
Submit a zero-day and be rewarded for your efforts.
Fix
Earn a reward by reviewing and fixing vulnerabilities.
Hacktivity
View maintainer approved disclosures and patches.
Submit your first disclosure
Help and resources for your first vulnerability disclosure.
Blog
Follow us on how we're protecting open source.
Responsible disclosure
Read our policy and understand what vulnerabilities are in scope.
FAQ
Find an answer to all the common questions you may have.
Contact us
Let us know your thoughts by getting in touch.
myliang/x-spreadsheet A web-based JavaScript spreadsheet. this package is vulnerable to Stored Cross-Site Scripting (XSS).
myliang/x-spreadsheet
Stored Cross-Site Scripting (XSS)
https://github.com/myliang/x-spreadsheet https://www.npmjs.com/package/x-data-spreadsheet
gdrive
run any javascript payloads