es-chromium: a Chromium build that tracks attacker-controlled data through V8 and Blink and reports DOM-XSS as a flow, not a guess. The browser agent behind EyalSec.
-
Updated
Aug 14, 2026
es-chromium: a Chromium build that tracks attacker-controlled data through V8 and Blink and reports DOM-XSS as a flow, not a guess. The browser agent behind EyalSec.
Intentionally vulnerable single-page dashboard demonstrating es-chromium DOM-XSS taint tracking - 21 flows across 8 sources and 18 sinks, each reachable from one URL. Demo target only.
Intentionally vulnerable Python app demonstrating EyalSec runtime taint tracking - one endpoint per source-to-sink vulnerability. Isolated lab use only.
To associate your repository with the eyalsec topic, visit your repo's landing page and select "manage topics."