Christopher Lemmer Webber @cwebber@octodon.social
Follow

@szbalint @joeyh not sure if you saw the Guile vulnerability that we uncovered a while ago where live hacking sessions listening on localhost were vulnerable to confused deputy attacks through browsers and etc (notably, also activitypub instances that don't heed this advice) that allowed arbitrary code execution lists.gnu.org/archive/html/gui

localhost-only ain't

· Web · 2 · 1