logo

Bypassing CSP with JSONP: Introducing JSONPeek and CSP B Gone

ID: 632456a4-d302-58d7-b939-45745968600d

STIX ID: report--632456a4-d302-58d7-b939-45745968600d

Feed Name: Black Hills Infosec Blog

Date Published: 2025-08-13

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog explains how JSONP endpoints can be abused to bypass Content Security Policy (CSP) and achieve XSS, demonstrates the technique with examples (including Google’s JSONP endpoint), and introduces two tools — JSONPeek for detecting JSONP callback parameters and CSP B Gone for automating CSP bypass discovery using a curated dataset of endpoints; the author also describes using BigQuery and headless testing to harvest and validate thousands of candidate endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.