Advisories for Npm/Nuclide package

2018

Improper Input Validation

The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a malicious URL could be used to render HTML and other content inside the editor's context, which could potentially be chained to lead to code execution.