Closed tomudding closed 5 months ago
It is currently possible to bypass the safety checks of the default Markdown editor to be able to render images through the default Markdown renderer.
![]() should always be rendered as text
![]()
TBA
06e37b2e379bb486758d8c342a89dc6f7d6b3561
No response
Is fixed by creating a custom CommonMarkCoreExtension that does not have the default ImageRenderer.
CommonMarkCoreExtension
ImageRenderer
Current behaviour
It is currently possible to bypass the safety checks of the default Markdown editor to be able to render images through the default Markdown renderer.
Desired behaviour
![]()
should always be rendered as textSteps to reproduce
TBA
Website version
06e37b2e379bb486758d8c342a89dc6f7d6b3561
What operating are you seeing the problem on?
No response
What browsers are you seeing the problem on?
No response
Other information
No response