-
-
Notifications
You must be signed in to change notification settings - Fork 1.5k
Closed
Labels
bug 🐛Issue concerns a bug.Issue concerns a bug.funded on issuehunt 💵Issue has received funding that will be rewarded to the contributor solving this issue.Issue has received funding that will be rewarded to the contributor solving this issue.rewarded on issuehunt 🎁Issue has been resolved and a contributor has been rewarded.Issue has been resolved and a contributor has been rewarded.security issue 🔑Issue concerns Boostnote's security. Usually high priority.Issue concerns Boostnote's security. Usually high priority.
Description
XSS
There is a xss in the newest version via a label named mermaid
When we insert codes like this:
graph LR
id1["<iframe src=javascript:alert('xss')></iframe>"]
we can see there is a xss in the latest version.

IssueHunt Summary
amedora has been rewarded.
Backers (Total: $40.00)
boostio ($40.00)
Submitted pull Requests
Tips
- Checkout the Issuehunt explorer to discover more funded issues.
- Need some help from other developers? Add your repositories on IssueHunt to raise funds.
IssueHunt has been backed by the following sponsors. Become a sponsor
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
bug 🐛Issue concerns a bug.Issue concerns a bug.funded on issuehunt 💵Issue has received funding that will be rewarded to the contributor solving this issue.Issue has received funding that will be rewarded to the contributor solving this issue.rewarded on issuehunt 🎁Issue has been resolved and a contributor has been rewarded.Issue has been resolved and a contributor has been rewarded.security issue 🔑Issue concerns Boostnote's security. Usually high priority.Issue concerns Boostnote's security. Usually high priority.