Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Escaping #4

Open
Steffo99 opened this issue Oct 30, 2023 · 1 comment
Open

Escaping #4

Steffo99 opened this issue Oct 30, 2023 · 1 comment
Labels
feature A request for a new feature.

Comments

@Steffo99
Copy link
Collaborator

Currently, no escaping at all is done on the HTML generated by Marked.

This can be a cause for XSS (but then again, there is nothing to be gained from performing XSS on one's own vault... or is there?).

@Steffo99 Steffo99 added the feature A request for a new feature. label Oct 30, 2023
@Steffo99
Copy link
Collaborator Author

This could also be used to XSS steffo.eu, I guess, but still: there's nothing there...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
feature A request for a new feature.
Projects
None yet
Development

No branches or pull requests

1 participant