Skip to content

locize Client SDK: Cross-origin DOM XSS & Handler Hijack Through Missing e.origin Validation in InContext Editor

High severity GitHub Reviewed Published Apr 18, 2026 in locize/locize • Updated May 13, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts