Open github-actions[bot] opened 2 years ago
XSS in comrak
comrak
0.7.0
>=0.9.1
The comrak we were matching unsafe URL prefixes, such as data: or javascript: , in a case-sensitive manner. This meant prefixes like Data: were untouched.
data:
javascript:
Data:
See advisory page for additional details.
comrak
0.7.0
>=0.9.1
The comrak we were matching unsafe URL prefixes, such as
data:
orjavascript:
, in a case-sensitive manner. This meant prefixes likeData:
were untouched.See advisory page for additional details.