DOM XSS via postMessage — Impact on staging.uipath.com

Attacker origin:

XSS target: apollo-composite.uipath.com (UiPath Apollo design system Storybook, shared infrastructure)

Impacted asset: staging.uipath.com — cookie tossing + PII theft via shared .uipath.com domain cookies

Framework: Stencil web components — forceRemount required to rebuild shadow DOM

CSP: None on Storybook — fetch() to external servers works

Interaction: One click — click the "Link" text inside the popup

Sink: ap-link component's href prop → <a href="..."> inside shadow DOM

Exfiltrated Data & Cookie Tossing Proof (staging.uipath.com)