I've decided to report it as a bug to code.org since I realize the devastating potential of an exploit like this. For now, I shall wait until it is patched. Cry about it, but it's the responsible thing to do.

    2 months later

    Binary_Coder Nope, never happened, and yes it is less dangerous without public project publishing.

    Awards

    • â’¸ 0.1 from Varrience
      Comment: Still can delete your account though lulz

    The main issue with the vulnerability is that it allows projects to run scripts that can literally delete or edit projects in your account. I could make a project, that, when run, copies it's source code to all of your projects and then auto publishes them to the public gallery, propagating the worm across cdo wiping millions of projects.

    Awards

      a month later
      16 days later

      Chat