1 min read
|
Saved February 14, 2026
|
Copied!
Do you care about this?
GMSGadget is a collection of JavaScript tools designed to bypass XSS mitigations like Content Security Policy and HTML sanitizers. The tools listed are not exploits but rather patched vulnerabilities or JavaScript behaviors that can circumvent HTML restrictions. Contributions for new gadgets and documentation improvements are encouraged.
If you do, here's more
GMSGadget, or Give Me a Script Gadget, is a curated set of JavaScript tools designed to bypass web security measures like Content Security Policy (CSP) and HTML sanitizers, including DOMPurify. The tools listed are not exploits themselves; they consist of either vulnerabilities that have been patched or standard JavaScript behaviors that can be manipulated to circumvent restrictions imposed by web applications.
The platform encourages community involvement, inviting users to contribute by submitting new gadgets, enhancing existing documentation, or reporting any issues. There are clear guidelines for participation, making it accessible for those interested in improving the resource. This collaborative approach aims to keep the collection relevant and up-to-date in the evolving landscape of web security.
Questions about this article
No questions yet.