Home / Companies / Gentrace / Blog / Post Details
Content Deep Dive

Security advisory: XSS vulnerability patched

Blog post from Gentrace

Post Details
Company
Date Published
Author
Doug Safreno
Word Count
353
Company Posts That Month
3
Language
English
Hacker News Points
-
Post removed?
No
Summary

On January 26th, a Gentrace customer reported a cross-site scripting (XSS) vulnerability found by a security consultant, which occurred due to unsanitized text rendered in OpenAI input and output blocks within the Gentrace UI. The issue was linked to the use of Mustache for interpolating content without automatic template sanitization. By January 28th, Gentrace addressed the vulnerability by escaping content before rendering and thoroughly scanning their production database, finding no malicious hits beyond the initial benign security test. To prevent future occurrences, Gentrace audited their codebase to ensure all user-generated content passed to React's dangerouslySetInnerHTML is sanitized with DOMPurify, and they implemented a react/no-danger eslint error to enforce safety checks during pull request reviews. With the fix in place and no users affected, no actions were recommended for customers, and Gentrace encouraged feedback on best practices while promoting their newsletter for updates and AI engineering insights.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
LLM 2 2,593 281 107 +38%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.