I wonder if javascript in notes is run by any client out there.
Immediate XSS if so, secrets exfil trivial after that
Please Login to reply.
No replies yet.