Skip to content

Sanitize subtitle html#905

Merged
killergerbah merged 1 commit intomainfrom
sanitize-subtitle-html
Mar 1, 2026
Merged

Sanitize subtitle html#905
killergerbah merged 1 commit intomainfrom
sanitize-subtitle-html

Conversation

@killergerbah
Copy link
Copy Markdown
Owner

I was able to reproduce an XSS attack by inserting <button onclick="alert('xss')">XSS BUTTON</button> into an SRT file and turning on the render html option. This change seems to prevent the button from functioning.

@cloudflare-workers-and-pages
Copy link
Copy Markdown

Deploying asbplayer with  Cloudflare Pages  Cloudflare Pages

Latest commit: 8430092
Status: ✅  Deploy successful!
Preview URL: https://a12597a4.asbplayer.pages.dev
Branch Preview URL: https://sanitize-subtitle-html.asbplayer.pages.dev

View logs

@killergerbah killergerbah merged commit 65f0cdc into main Mar 1, 2026
2 checks passed
@killergerbah killergerbah deleted the sanitize-subtitle-html branch March 1, 2026 01:47
@killergerbah killergerbah added this to the Extension v1.15.0 milestone Mar 1, 2026
khajiitvaper2017 pushed a commit to khajiitvaper2017/asbplayer that referenced this pull request Mar 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants