Skip to content

markdown: sanitize markdown-it renderer output#1442

Merged
cmouse merged 1 commit intodovecot:mainfrom
slusarz:sanitize_markdown
Mar 2, 2026
Merged

markdown: sanitize markdown-it renderer output#1442
cmouse merged 1 commit intodovecot:mainfrom
slusarz:sanitize_markdown

Conversation

@slusarz
Copy link
Contributor

@slusarz slusarz commented Feb 27, 2026

Fix stored XSS vulnerabilities in the dovecot_markdown plugin.

This is generally useful to catch any kind of special characters to ensure proper HTML display anyway.

Fix stored XSS vulnerabilities in the dovecot_markdown plugin.

This is generally useful to catch any kind of special characters
to ensure proper HTML display anyway.
@cmouse cmouse force-pushed the sanitize_markdown branch from 33721dc to 1c21c78 Compare March 2, 2026 10:42
@cmouse cmouse enabled auto-merge (rebase) March 2, 2026 10:42
@cmouse cmouse merged commit 59b349b into dovecot:main Mar 2, 2026
5 checks passed
@slusarz slusarz deleted the sanitize_markdown branch March 3, 2026 07:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants