CVE-2021-29467

Publication date

2021-04-22 00:05:16

Family

GitHub_M

State

PUBLISHED

Description

Wrongthink is an encrypted peer-to-peer chat program. A user could check their fingerprint into the service and enter a script to run arbitrary JavaScript on the site. No workarounds exist, but a patch exists in version 2.4.1.