You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We should extend the scope of #847 then. @knsv has added your example to the issue so please watch it for any relevant updates. I will close this issue for now.
Hi, I found XSS issues in mermaid. This affects all the projects that use mermaid.
There are three different ways to trigger.
The first one:
The second one:
The third one(needs click, both nodes will work):
Here is an example that affects other projects which using mermaid.
hackmdio/codimd#1233
And all above three payload would work on hackmd.io
Hope you can fix soon!
The text was updated successfully, but these errors were encountered: