Skip to content

Security review — multiple findings: 2 potential issues #11763

Description

@aldiboncel49-lgtm

Potential security concerns in OneKeyHQ/app-monorepo

Found 4 items: 0 critical, 2 high, 2 medium, 0 low.

potential-xss -- packages/kit/src/components/WebView/translateInject.js line 365

Severity: HIGH

Language: JS/TS

Potential XSS

span.innerHTML = SPINNER_SVG;

potential-hardcoded-credentials -- packages/shared/src/modules3rdParty/stripe-v3/index.js line 1

Severity: HIGH

Language: JS/TS

Potential hardcoded credentials

!function(){function e(t){var n=o[t];if(void 0!==n)return n.exports;var i=o[t]={id:t,loaded:!1,exports:{}};return rt,i.loaded=!0,i.exports}var t,n,r={723:function(e,t,n){"use strict";

Some of these might be false positives. Happy to provide more context if any look actionable.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions