-
-
Notifications
You must be signed in to change notification settings - Fork 173
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Bug] Highlighter 组件有 XSS 漏洞 #176
Comments
👀 @Carrotzpc |
✅ @Carrotzpc |
github-actions bot
pushed a commit
that referenced
this issue
Jul 18, 2024
### [Version 1.146.9](v1.146.8...v1.146.9) <sup>Released on **2024-07-18**</sup> #### 🐛 Bug Fixes - **misc**: Fix XSS. <br/> <details> <summary><kbd>Improvements and Fixes</kbd></summary> #### What's fixed * **misc**: Fix XSS, closes [#176](#176) ([4ea87cf](4ea87cf)) </details> <div align="right"> [data:image/s3,"s3://crabby-images/1c55b/1c55b139b5b5b56e7af50d766f83d46712efcde4" alt=""](#readme-top) </div>
github-actions bot
pushed a commit
to bentwnghk/lobe-ui
that referenced
this issue
Jul 18, 2024
### [Version 1.18.6](v1.18.5...v1.18.6) <sup>Released on **2024-07-18**</sup> #### 🐛 Bug Fixes - **misc**: Fix XSS. <br/> <details> <summary><kbd>Improvements and Fixes</kbd></summary> #### What's fixed * **misc**: Fix XSS, closes [lobehub#176](https://github.com/bentwnghk/lobe-ui/issues/176) ([4ea87cf](4ea87cf)) </details> <div align="right"> [data:image/s3,"s3://crabby-images/1c55b/1c55b139b5b5b56e7af50d766f83d46712efcde4" alt=""](#readme-top) </div>
ReneDrengen
pushed a commit
to ReneDrengen/lobe-ui
that referenced
this issue
Sep 18, 2024
ReneDrengen
pushed a commit
to ReneDrengen/lobe-ui
that referenced
this issue
Sep 18, 2024
### [Version 1.146.9](lobehub/lobe-ui@v1.146.8...v1.146.9) <sup>Released on **2024-07-18**</sup> #### 🐛 Bug Fixes - **misc**: Fix XSS. <br/> <details> <summary><kbd>Improvements and Fixes</kbd></summary> #### What's fixed * **misc**: Fix XSS, closes [lobehub#176](lobehub#176) ([4ea87cf](lobehub@4ea87cf)) </details> <div align="right"> [data:image/s3,"s3://crabby-images/1c55b/1c55b139b5b5b56e7af50d766f83d46712efcde4" alt=""](#readme-top) </div>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
💻 系统环境 | Operating System
Windows
🌐 浏览器 | Browser
Chrome
🐛 问题描述 | Bug Description
如果 code 中包含 html 标签,而且解析失败的话,走到 catch 里面 html 标签会直接渲染,别问我怎么知道的。。。
lobe-ui/src/hooks/useHighlight.ts
Lines 60 to 62 in 532c5bf
🚦 期望结果 | Expected Behavior
需要在解析失败后对 code 进行转义
📷 复现步骤 | Recurrence Steps
No response
📝 补充信息 | Additional Information
No response
The text was updated successfully, but these errors were encountered: