HTML input in issue comments aren't sanitized. This is a potential XSS vulnerability. I know GitHub markdown supports some HTML, but I believe there is a blacklist of elements like script tags that should at least be neutralized.
I've tested this on iOS 12.3.1 and GitHawk 1.27.2. To test, please visit this issue via GitHawk.
XSS Demo
Sanitize untrusted HTML (to prevent XSS) with a configuration specified by a whitelist is good practice.
HTML input in issue comments aren't sanitized. This is a potential XSS vulnerability. I know GitHub markdown supports some HTML, but I believe there is a blacklist of elements like script tags that should at least be neutralized.
I've tested this on iOS 12.3.1 and GitHawk 1.27.2. To test, please visit this issue via GitHawk.
XSS Demo
Sanitize untrusted HTML (to prevent XSS) with a configuration specified by a whitelist is good practice.
https ftp other link 1 other link 2 other link 3 javascript link