Skip to content

XSS: Javascript execution through links #221

@iamareebjamal

Description

@iamareebjamal

Posting this:

[Just Regular Link](javascript:alert(1))

Renders

A link which will show alert on click. Should this be considered an XSS vulnerability and mitigated by library itself or by the users by creating a custom parser?

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions