I’m not following your argument here. I’m at times critical of Bubble and it’s security, but this isn’t one of those times.

If you had your own Bubble “instance” as you quote, you’d be having the exact same issue. If you ran a fully custom web app that required this package, you’d be having the exact same issue.

It’s not Bubble’s fault a third-party package was infected. You could have solved this issue yourself, with or without Bubble, by deleting the package or installing some level of CSP.

1 Like