Skip to content

"content_security_policy" allows remote code execution in manifest.json #15603

Closed Answered by wpplumber
wpplumber asked this question in CLI - BEX mode
Discussion options

You must be logged in to vote

I made the following changes and fixed:

  • "content_security_policy": "default-src 'self'"

  • Using Node.textContent

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by wpplumber
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
1 participant