Skip to content

Malicious comment makes loading fails for all other comments

This is a manual import of https://hackerone.com/reports/860559 as this vulnerability makes the automated import #215974 (closed) fail

@gweaver @johnhope When commenting an issue with the following payload it makes loading of all the other comments fail when refreshing the page:

![a](/uploads/%00)

Edited by Jeremy Matos