Skip to content

Insufficient sanitization of urls #2596

Open
@knsv

Description

@knsv

Malicious diagrams can contain javascript code that can be run at diagram readers machines.

Activity

added
Type: Bug / ErrorSomething isn't working or is incorrect
Status: TriageNeeds to be verified, categorized, etc
on Dec 29, 2021
jgreywolf

jgreywolf commented on Apr 6, 2023

@jgreywolf
Contributor

@knsv status?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Status: TriageNeeds to be verified, categorized, etcType: Bug / ErrorSomething isn't working or is incorrect

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

    Development

    No branches or pull requests

      Participants

      @jgreywolf@knsv

      Issue actions

        Insufficient sanitization of urls · Issue #2596 · mermaid-js/mermaid