Major Security Flaw Found in Greasemonkey: The best round-up I’ve seen so far of all the issues and information surrounding the recently-discovered Greasemonkey vulnerability.
If a user running a vulnerable version of Greasemonkey visits a website that triggers at least one of their user scripts then that website can read any of the user’s files or list the contents of any of the user’s directories/folders.
Greasemonkey 0.4.1 (The Next Generation): Apparently Greasemonkey has been gutted and put back together to fix the huge security hole in the last version. I can confim that, despite massive architectural differences, GM-TNG is incredibly backward-compatible, even with complex user scripts like Book Burro, BugMeNot, and GMail Persistent Searches.…