Web Hack List

Other nomination

Bypassing CSP via URL Parser Confusions: XSS on Netlify’s Image CDN

A stored cross-site scripting finding on Netlify's image CDN endpoint. An upload allowlist that trusted the declared Content-Type let arbitrary HTML be hosted on a whitelisted CDN origin, and the image proxy served it back verbatim; the strict script-src 'none' policy applied to that path was shed by requesting an encoded or doubled-slash variant that the edge did not match but the backend normalised. The resulting script stole an OAuth authorization response.

Record

Researcher
sudi
Published by
sudi’s blog
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of sudi, first published at the original source. Preserved copies are kept so the citation survives its host.