Vulnerabilities/

HFS user adding a "web link" in HFS is vulnerable to "target=_blank" exploit

Severity:
Low

Description

When adding a “web link” to the HFS virtual filesystem, the frontend opens it with target="_blank" but without the rel="noopener noreferrer" attribute. This allows the opened page to use the window.opener property to change the location of the original HFS tab.

Recommendation

Update the hfs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
hfs
Anything's wrong? Let us know Last updated on August 12, 2025

This issue is available in SmartScanner Professional

See Pricing