← Back to index

IAST postMessage Misuse Module

Tests window.postMessage sinks with tainted payloads and wildcard origin.

Choose which source to prime for the message payload.

Taint is read from ?payload=... or the textarea when you click "Prime taint sources".

Cross-origin target triggers postmessage_cross_origin_leak.

Sandboxed iframe to receive postMessage events.