| 概要 | Logseq is vulnerable to a sandbox escape flaw where plugins running in sandboxed iframes can inject arbitrary HTML attributes, such as event handlers, into their container element in the host DOM. Due to a disabled Content Security Policy (CSP), this allows a malicious plugin to execute arbitrary JavaScript in the privileged host context, potentially gaining unauthorized access to filesystem APIs. |
|---|---|
| 公表日 | 2026年6月9日23:16 |
| 登録日 | 2026年6月10日4:16 |
| 最終更新日 | 2026年6月9日23:47 |