Headline
CVE-2021-44907: Edit fiddle - JSFiddle - Code Playground
A Denial of Service vulnerability exists in qs up to 6.8.0 due to insufficient sanitization of property in the gs.parse function. The merge() function allows the assignment of properties on an array in the query. For any property being assigned, a value in the array is converted to an object containing these properties. Essentially, this means that the property whose expected type is Array always has to be checked with Array.isArray() by the user. This may not be obvious to the user and can cause unexpected behavior.
Run
Save
Fork
Set as base
Collaborate
- Settings
- Sign in
Editor layout
Classic Columns Bottom results Right results Tabs (columns) Tabs (rows)
Console
Console in the editor (beta)
Clear console on run
General
Line numbers
Wrap lines
Indent with tabs
Code hinting (autocomplete) (beta)
Behavior
Auto-run code
Only auto-run code that validates
Auto-save code (bumps the version)
Auto-close HTML tags
Auto-close brackets
Live code validation
Highlight matching tags
Boilerplates
Show boilerplates bar less often
Save anonymous (public) fiddle?
- Be sure not to include personal data
- Do not include copyrighted material
Log in if you’d like to delete this fiddle in the future.
Fork anonymous (public) fiddle?
- Be sure not to include personal data
- Do not include copyrighted material
Log in if you’d like to delete this fiddle in the future.
Tabs:
JavaScript HTML CSS Result
Visual:
Light Dark
Embed snippet Prefer iframe?:
No autoresizing to fit the code
Render blocking of the parent page
Fiddle meta
Resources URL cdnjs 0
- Paste a direct CSS/JS URL
- Type a library name to fetch from CDNJS
Async requests
/echo
simulates Async calls:
JSON: /echo/json/
JSONP: //jsfiddle.net/echo/jsonp/
HTML: /echo/html/
XML: /echo/xml/
See docs for more info.
Other (links, license)
Created and maintained by Piotr and Oskar.
Hosted on DigitalOcean
All code belongs to the poster and no license is enforced. JSFiddle or its authors are not responsible or liable for any loss or damage of any kind during the usage of provided code.
Links
Bug tracker
Roadmap (vote for features)
About
Docs
Service status
Language****Doctype****Body tag
Language****Frameworks & Extensions****Framework <script> attribute
Language****Options
Normalized CSS
- This fiddle has previously unsaved changes. Apply changes Discard
IE is no longer supported 📠