-
Notifications
You must be signed in to change notification settings - Fork 33
Open
Labels
Milestone
Description
We allow anchors in the default configuration and only restrict javascript: URLs. data: URLs (especially inside an iframe) might look like XSS: https://x.com/KwanAleister/status/1985542748930523233
Personally I don't think data: URLs are special here, you could also link to a HTTP page that shows an alert. I filed this issue mainly for tracking.
Reactions are currently unavailable