
Just shipped my first open source security contribution 🔐. I ran a Trivy SAST scan on @formbricks, found a CRITICAL stored XSS vulnerability (CVE-2026-44990, CVSS 9.3), reproduced it locally, and opened a PR with the fix. Here's the full breakdown:
Post summary
The tweet announces the identification of a critical stored XSS vulnerability, provides its technical details, and notes that a fix is being merged via a pull request.


