Skip to content

[BUG] [GSSoC'26] express-session cookie lacks httpOnly, Secure, and SameSite flags: all authenticated sessions are vulnerable to XSS hijack and CSRF #205

[BUG] [GSSoC'26] express-session cookie lacks httpOnly, Secure, and SameSite flags: all authenticated sessions are vulnerable to XSS hijack and CSRF

[BUG] [GSSoC'26] express-session cookie lacks httpOnly, Secure, and SameSite flags: all authenticated sessions are vulnerable to XSS hijack and CSRF #205