Security: abrignoni/ALEAPP
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
-
Stored HTML/JavaScript injection in HTML report cells: evidence-derived values listed in an artifact's `html_columns` are written to the HTML report without escaping, so malicious content in a parsed extraction/return can execute JavaScript in the examiner's browser when the report is opened.GHSA-9xqw-4qrc-5qp5 published
Jul 25, 2026 by abrignoniModerate
Learn more about advisories related to abrignoni/ALEAPP in the GitHub Advisory Database