tanabe / markdown-live-preview

markdown editor with live preview
https://markdownlivepreview.com/
MIT License
236 stars 57 forks source link

Self-XSS #18

Closed Marnick39 closed 4 years ago

Marnick39 commented 4 years ago

All js between script tags gets executed. I can't easily find a way to use this to attack other users, but it might be best to tame the beast while it is small.

image

tanabe commented 4 years ago

@Marnick39

Thanks for opening this issue. I think also this small at the moment. But I'll fix this.