FlowiseAI / FlowiseChatEmbed

278 stars 1.18k forks source link

fix: xss vulnerability #116

Closed kweripx closed 1 month ago

kweripx commented 3 months ago

because of the markdown, a user can send a script on the chat. This changes remove the markdown from user message, preventing the user to send scripts inside html tags

HenryHengZJ commented 1 month ago

fix opened - https://github.com/FlowiseAI/FlowiseChatEmbed/pull/168