diff --git a/.jules/sentinel.md b/.jules/sentinel.md index 08e5bfbd..7a204c2a 100644 --- a/.jules/sentinel.md +++ b/.jules/sentinel.md @@ -6,4 +6,7 @@ ## 2025-03-08 - Unsafe SVG Rendering via dangerouslySetInnerHTML **Vulnerability:** User-controlled SVG strings (`avatar.svg_data`) were being injected directly into the DOM using `dangerouslySetInnerHTML`. An attacker could inject an SVG containing embedded malicious `