Skip to content

fix: escape HTML in image, link, and media components#2718

Open
sy-records wants to merge 1 commit intodevelopfrom
fix/xss
Open

fix: escape HTML in image, link, and media components#2718
sy-records wants to merge 1 commit intodevelopfrom
fix/xss

Conversation

@sy-records
Copy link
Copy Markdown
Member

@sy-records sy-records commented Apr 9, 2026

Summary

escape HTML in image, link, and media components to prevent XSS vulnerabilities

Related issue, if any:

What kind of change does this PR introduce?

  • Bugfix
  • Feature
  • Code style update (formatting, renaming)
  • Refactoring (no functional changes, no api changes)
  • Build related changes
  • Documentation content changes
  • Other (please describe):

For any code change,

  • Related documentation has been updated, if needed
  • Related tests have been added or updated, if needed

Does this PR introduce a breaking change?

  • Yes
  • No

Tested in the following browsers:

  • Chrome
  • Firefox
  • Safari
  • Edge

@vercel
Copy link
Copy Markdown

vercel bot commented Apr 9, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
docsify-preview Ready Ready Preview, Comment Apr 9, 2026 4:12am

@sy-records sy-records requested a review from paulhibbitts April 9, 2026 04:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant