walle / gimli

Utility for converting markup files to pdf files
https://github.com/walle/gimli
MIT License
538 stars 44 forks source link

RedCloth XSS vulnerability #74

Open ghost opened 8 years ago

ghost commented 8 years ago

There is a known XSS vulnerability in RedCloth which was reported 2012 and didn't get fixed until now. RedCloth seems to have some difficulties maintaining and closing bugs. Did you consider using Redcarpet?

Link: http://co3k.org/blog/redcloth-unfixed-xss-en