Skip to content

Potentially malicious links in Markdown previews are clickable #99

@btrask

Description

@btrask

In our preview generator for CommonMark Markdown files, we allow clickable links, including hash: links. That means we don't use cmark's "safe" link checker that prohibits javascript: links, among other protocols.

We should probably maintain our own whitelist.

  • http
  • hash
  • data?
  • ftp
  • NOT file
  • mailto

Let's look at cmark to see what else.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions