Unknown · Hubs Cloud · CVE-2021-29979
**Name of the Vulnerable Software and Affected Versions**
Hubs Cloud versions prior to 1.0.1/20210618012634
**Description**
The issue allows users to download shared content, specifically HTML and JS, which could enable javascript execution in the Hub Cloud instance's primary hosting domain.
**Recommendations**
For versions prior to 1.0.1/20210618012634, consider restricting the download of shared HTML and JS content to prevent potential javascript execution in the primary hosting domain. As a temporary workaround, consider disabling the feature that allows users to download shared content until a patch is available.