Source status: Striga's tracker provides the AI-system attribution. Electron's public advisory and CVE record independently corroborate the fixed vulnerability but credit the human reporter, so the entry remains self-reported.
Summary
An unsanitized dock-state parameter could inject JavaScript into Electron DevTools under the advisory’s conditions. The upstream record validates the issue; only Striga’s own public tracker connects it to the platform.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.