Skip to content

[ENG-5784] Restrict update_vars_internal to browser storage vars#5293

Merged
adhami3310 merged 1 commit intomainfrom
masenf/restrict-update-vars-internal
May 14, 2025
Merged

[ENG-5784] Restrict update_vars_internal to browser storage vars#5293
adhami3310 merged 1 commit intomainfrom
masenf/restrict-update-vars-internal

Conversation

@masenf
Copy link
Copy Markdown
Collaborator

@masenf masenf commented May 14, 2025

Only allow reflex API event update_vars_internal to update vars associated with client storage values.

[CVE-2025-47425]
[GHSA-rf8x-9mhr-49wg]

Only allow reflex API event `update_vars_internal` to update vars associated
with client storage values.

[CVE-2025-47425]
[GHSA-rf8x-9mhr-49wg]
@linear
Copy link
Copy Markdown

linear bot commented May 14, 2025

@codspeed-hq
Copy link
Copy Markdown

codspeed-hq bot commented May 14, 2025

CodSpeed Performance Report

Merging #5293 will not alter performance

Comparing masenf/restrict-update-vars-internal (ca978b0) with main (dcb1c10)

Summary

✅ 8 untouched benchmarks

@adhami3310 adhami3310 merged commit cf8f5db into main May 14, 2025
42 checks passed
@adhami3310 adhami3310 deleted the masenf/restrict-update-vars-internal branch May 14, 2025 18:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants