Vulnrability: XSS #3

Closed
opened 2025-04-06 09:06:20 +02:00 by seth · 1 comment

As stated directly from the README, "Marked does not sanitize the output HTML."

{C445BA95-0BD7-4574-BB9D-B97727756371}
{4F4244E2-97A4-4990-819B-C128A92E704B}

A live example can be seen here: https://creations.works/1273447359417942128

Please view their README here to see what they recommend.

As stated directly from the README, "Marked does not sanitize the output HTML." ![{C445BA95-0BD7-4574-BB9D-B97727756371}](/attachments/dc192828-cc26-4f02-890b-8478a911170a) ![{4F4244E2-97A4-4990-819B-C128A92E704B}](/attachments/8888ee8a-531d-458a-8856-09711da98ed6) A live example can be seen here: https://creations.works/1273447359417942128 Please view their README [here](https://github.com/markedjs/marked?tab=readme-ov-file#warning--marked-does-not-sanitize-the-output-html-please-use-a-sanitize-library-like-dompurify-recommended-sanitize-html-or-insane-on-the-output-html-) to see what they recommend.
Author

this could also be seen as a feature?

~~this could also be seen as a feature?~~
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: creations/profilePage#3
No description provided.