We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Describe the bug Articles with <img onerror="alert(1)"></img> in the body trigger XSS
<img onerror="alert(1)"></img>
To Reproduce Steps to reproduce the behavior:
Expected behavior The body is shown without an alert triggering
Screenshots
The problem in the code is here. pulldown_cmark doesn't sanitize.
pulldown_cmark
The text was updated successfully, but these errors were encountered:
No branches or pull requests
Describe the bug
Articles with
<img onerror="alert(1)"></img>
in the body trigger XSSTo Reproduce
Steps to reproduce the behavior:
Expected behavior
The body is shown without an alert triggering
Screenshots
The problem in the code is here.
pulldown_cmark
doesn't sanitize.The text was updated successfully, but these errors were encountered: