Merge pull request #287 from adrianosela/main

[CVE-2024-51735/GHSA-wvv7-wm5v-w2gv] Fix XSS In Markdown Resolver
This commit is contained in:
Ai Ho (j3ssie)
2025-02-03 14:54:52 +07:00
committed by GitHub
+2
View File
@@ -2,6 +2,7 @@ package core
import (
"path"
"text/template"
"fmt"
"os"
@@ -111,6 +112,7 @@ func (r *Runner) ResolveContentSrc(tag string) string {
}
if strings.Contains(tag, "shorten=true") || len(fileContent) > r.Opt.MDCodeBlockLimit {
fileContent = template.HTMLEscapeString(fileContent) // sanitize file content to prevent XSS
return extendTag(fileContent)
}