| Summary | Logseq is vulnerable to a sandbox escape flaw where plugins running in sandboxed iframes can inject arbitrary HTML attributes, such as event handlers, into their container element in the host DOM. Due to a disabled Content Security Policy (CSP), this allows a malicious plugin to execute arbitrary JavaScript in the privileged host context, potentially gaining unauthorized access to filesystem APIs. |
|---|---|
| Publication Date | June 9, 2026, 11:16 p.m. |
| Registration Date | June 10, 2026, 4:16 a.m. |
| Last Update | June 9, 2026, 11:47 p.m. |