Possible injection because of sanitize cache
未关闭
- 主要语言
- JavaScript
- 星标
- 814
- 派生
- 37
- PR 合并指标
- 30 天内没有已合并 PR
描述
Basically it's possible to inject dirty html:
```js
const striked = 'test';
console.log(
{striked}
);
console.log(
test
);
console.log(
{striked}
);
```
This is the output:
```html
<strike>test</strike>
test
test
```
Expected output:
```html
<strike>test</strike>
test
<strike>test</strike>
```
After rendering `
test
`, it caches `test` and doesn't sanitize it anymore. It can be seen live [here](https://codepen.io/remziatay/pen/YzroqLm?editors=1010) as well. Just because something was rendered before, it shouldn't mean that it's sanitized.
贡献指南
这个仓库没有索引到贡献指南
评估
这个 Issue 还没有评估数据。