DEV Community

Discussion on: Injecting a JavaScript Attack Vector using CSS Custom Properties

Collapse
 
lionelrowe profile image
lionel-rowe

I'm not sure if this is intentionally clickbaitey, but there's nothing new or particularly special about this attack vector. If an attacker can inject the code containing the eval or Function, they already own your site. The fact the payload happens to be stored in a CSS custom property has nothing to do with it.