Hacker News new | ask | show | jobs
by lumpa 1965 days ago
The repo reads like research code, and indeed seems to be an article's companion code plus platform example code. The code in question was committed in 2018 and never touched again.

That's no excuse, it pretty literally does "innerhtml = user_input" and it's awful. But it's not a flagship chatbot library from what I see, which probably lessens the impact of such awfulness.

1 comments

partially agree. In another repo, the same vulnerability was only fixed after years ...

https://github.com/watson-developer-cloud/assistant-simple/c...