4 hours ago

@GarboMuffin just shared a blog post disclosing an XSS vulnerability found in the unmaintained "paper.js" (the vector rendering library used by Scratch and its forks).

The article is a list of mods (as I find) that are still vulnerable. Avoid using these.


  • Gandi IDE (Cocrea)

  • Creaticode

  • ScratchCE

Link to the blog post:

https://muffin.ink/blog/paperjs-xss/



0 comments

Loading...

Next up

People in the comments are talking like 4.0 is a rumour when it's been confirmed for months, possibly years now.

Honestly it's been a long time coming. I think even the devs are sick of their archaic version of Blockly.

Trying out this "warpspeed" thing people are yapping on about.

Don't make a mistake or you won't be able to undo.

i'd appreciate suggestions for what other quick settings i should put here

The Scratch Team has just recently updated their Terms of Service yesterday, letting you know they now have full permission to use your content to train AI models.

Useless Scratch facts # 5:

An early version for a dark mode was implemented in the High-Contrast update, however it goes unused.

TurboWarp implemented it as the "Dark (Beta)" option. It's marked as beta because it's subject to upstream changes.

ok i FINALLY finished dropsane teto

i think i still got it

Also, yes, in a form of poetry, having the addon AND this option enabled will just flip the stage twice with some minor layout changes. Beautiful.

Yo Codin House Office

A "bug report" I received today reminded me that I had a plan a while ago that adding an internal settings menu makes a lot easier to add.

Welcome back, old friend.