Skip to content

Add test11.html postMessage demo#33

Open
alan-hacktron wants to merge 1 commit into
mainfrom
xss-postmessage-finding
Open

Add test11.html postMessage demo#33
alan-hacktron wants to merge 1 commit into
mainfrom
xss-postmessage-finding

Conversation

@alan-hacktron

@alan-hacktron alan-hacktron commented Jun 22, 2026

Copy link
Copy Markdown
Owner

Adds test11.html — a postMessage receiver demo page.

Note: This file contains a known high-severity XSS finding to validate the CI severity gate:

No origin validation on the message event listener
Direct innerHTML assignment of untrusted event.data
This PR is intentionally testing the Org threshold triggers fail case: org threshold = High, PR with High finding → CI should fail.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant