htmlpreview / htmlpreview.github.com

HTML Preview for GitHub Repositories
htmlpreview.github.com
1.51k stars 303 forks source link

xss on the webpage (bug or feature, no idea) #103

Open esp0xdeadbeef opened 3 years ago

esp0xdeadbeef commented 3 years ago

There is an simple XSS inside my repo, if you click on the following link, javascript will be executed.

https://htmlpreview.github.io/?https://github.com/esp0xdeadbeef/htmlpreviewxss/blob/main/README.md

XhmikosR commented 2 years ago

@niutech https://lgtm.com/projects/g/htmlpreview/htmlpreview.github.com?mode=list

You can add the CodeQL Action which is the successor of LGTM (both are owned by GitHub).