We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
An attacker can execute arbitrary JavaScript on users' browsers by posting links to malicious GitHub commits.
This problem is patched in the latest version of discourse-code-review plugin.
Disable plugin.
Impact
An attacker can execute arbitrary JavaScript on users' browsers by posting links to malicious GitHub commits.
Patches
This problem is patched in the latest version of discourse-code-review plugin.
Workarounds
Disable plugin.