Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
collinmanderson
77 days ago
|
parent
|
context
|
favorite
| on:
We pwned X, Vercel, Cursor, and Discord through a ...
If it’s running code outside of a normal browser sandbox then, yes it’s a RCE. Because it can now access to nearly everything on the user’s computer, including their browser, email, etc.
XSS is limited to accessing just that one website.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search:
XSS is limited to accessing just that one website.