Skip to content

Conversation

@Rello
Copy link
Owner

@Rello Rello commented Dec 19, 2025

Summary

  • add a SECURITY_REVIEW describing stored XSS vectors in dataset status and dataload views with mitigation recommendations
  • escape rendered report and dataload names and sanitize stored names when creating, updating, copying, or importing reports and dataloads
  • update the changelog to record the new security fixes and review documentation

Testing

  • Not run (not requested)

Codex Task

@Rello Rello closed this Dec 27, 2025
@Rello Rello deleted the codex/investigate-app-for-security-risks branch December 27, 2025 15:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants