You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Do not allow users to upload any file type, without any restrictions on file size or type. An attacker could potentially upload a malicious image file.
What is a poisoned image? Are we just talking about ip leakage and read receipts? If so, I'm not sure how you can have a full-featured UX without running afoul of that. The same vulnerability would apply to any clickable link too. In the future I might add a setting to turn off images/links, or proxy them through a server, but it's not a huge priority for coracle right now.
Do not allow users to upload any file type, without any restrictions on file size or type. An attacker could potentially upload a malicious image file.
I tested by uploading QR code image, pdf etc. generated here: https://canarytokens.org/generate
The text was updated successfully, but these errors were encountered: