Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

dependency vulnerability: DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS #30 #4260

Open
rysweet opened this issue Nov 18, 2024 · 0 comments
Assignees
Labels
proj-studio Related to AutoGen Studio.
Milestone

Comments

@rysweet
Copy link
Collaborator

rysweet commented Nov 18, 2024

What happened?

https://github.com/microsoft/autogen/security/dependabot/30

What did you expect to happen?

alert is remediated

How can we reproduce it (as minimally and precisely as possible)?

see https://github.com/microsoft/autogen/security/dependabot/30

AutoGen version

0.4

Which package was this bug in

AutoGen Studio

Model used

No response

Python version

No response

Operating system

No response

Any additional info you think would be helpful for fixing this bug

No response

@rysweet rysweet added this to the 0.4.0 milestone Nov 18, 2024
@victordibia victordibia added the proj-studio Related to AutoGen Studio. label Nov 19, 2024
victordibia added a commit that referenced this issue Nov 23, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
proj-studio Related to AutoGen Studio.
Projects
None yet
Development

No branches or pull requests

2 participants