TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

We used chatbot code from IBM, and it was instantly vulnerable to XSS attacks

3 pointsby ftremlover 4 years ago

2 comments

lumpaover 4 years ago
The repo reads like research code, and indeed seems to be an article&#x27;s companion code plus platform example code. The code in question was committed in 2018 and never touched again.<p>That&#x27;s no excuse, it pretty literally does &quot;innerhtml = user_input&quot; and it&#x27;s awful. But it&#x27;s not a flagship chatbot library from what I see, which probably lessens the impact of such awfulness.
评论 #26003794 未加载
ftremlover 4 years ago
I wrote about security threats for chatbots<p><a href="https:&#x2F;&#x2F;floriantreml.medium.com&#x2F;security-threats-and-security-testing-for-chatbots-325d704da9af" rel="nofollow">https:&#x2F;&#x2F;floriantreml.medium.com&#x2F;security-threats-and-securit...</a>