Security: kunchenguid/lavish-axi
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Cross-origin token theft via /whiteboard-frame CSP exemption (inline whiteboard channel token)GHSA-w887-pf37-frrv published
Aug 11, 2026 by kunchenguidModerate -
DNS rebinding allows any website to read arbitrary local files and inject prompts into the AI agent via the unauthenticated local serverGHSA-fwx2-qmmq-qvx2 published
Jul 22, 2026 by kunchenguidHigh
Learn more about advisories related to kunchenguid/lavish-axi in the GitHub Advisory Database