Vulnerability Report: Malicious filename can be used for self-XSS / HTML injection locally for users (CVE-2025-64711)
Dragging a file whose filename contains HTML is reflected verbatim into the page via the drag-and-drop helper. (CVE-2025-64711)
more ...