Nuclide Improper Input Validation
        
  Critical severity
        
          GitHub Reviewed
      
        Published
          May 13, 2022 
          to the GitHub Advisory Database
          •
          Updated May 6, 2025 
      
  
Description
        Published by the National Vulnerability Database
      Dec 31, 2018 
    
  
        Published to the GitHub Advisory Database
      May 13, 2022 
    
  
        Reviewed
      Jul 21, 2023 
    
  
        Last updated
      May 6, 2025 
    
  
The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a malicious URL could be used to render HTML and other content inside of the editor's context, which could potentially be chained to lead to code execution. This issue affected Nuclide prior to v0.290.0.
References