Missing origin check in message handler
Overview
Description
Remediation Guidelines
window.addEventListener('message', (event) => { actOnMessage(event.data) // unsafe });window.addEventListener('message', (event) => { if (event.origin != 'https://myapp.example.com') { throw new Error('invalid origin') } actOnMessage(event.data) })
References
Configuration
Last updated