BigHugger
sk Skill · elementalsouls

hunt-dom

Hunt client-side DOM vulnerabilities — DOM Clobbering (overwrite JS globals via HTML injection), PostMessage hijacking (missing origin check), Service Worker abuse (intercept requests from same-origin script), CSS Injection/Exfiltration (attribute selectors → token char-by-char via OOB), client-side template injection, dangerouslySetInnerHTML. Grounded in named public research: Gareth Heyes / PortSwigger…

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
pythonjavascriptcssbashhtmlPython
Host repository
elementalsouls/Claude-BugHunter
Host stars
4,524
Host language
Python