4 ms·
We used chatbot code from IBM, and it was instantly vulnerable to XSS attacks
- ftreml 6y agoI wrote about security threats for chatbots https://floriantreml.medium.com/security-threats-and-security-testing-for-chatbots-325d704da9af https://floriantreml.medium.com/security-threats-and-securit...
- lumpa 6y agoThe repo reads like research code, and indeed seems to be an article's companion code plus platform example code. The code in question was committed in 2018 and never touched again. That's no excuse, it pretty literally does "innerhtml = user_input" and it's awful. But it's not a flagship chatbot library from what I see, which probably lessens the impact of such awfulness.
- ftreml 6y agopartially agree. In another repo, the same vulnerability was only fixed after years ... https://github.com/watson-developer-cloud/assistant-simple/commit/c81eba5c6b23ad2658c8f0504d445c199d9e3fdc#diff-d35736fdc17f60aa62c35a24b542c637 https://github.com/watson-developer-cloud/assistant-simple/c...