Skip to content

Commit 8a5aaa1

Browse files
committed
security: prevent script tag from rendering (scripT or sCrIpT)
1 parent 7e90d70 commit 8a5aaa1

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

src/runtime/components/MDCRenderer.vue

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -195,7 +195,7 @@ function _renderNode(node: MDCNode, h: CreateElement, options: MDCRenderOptions,
195195
196196
// Prevent script execution by converting dangerous tags to pre tags
197197
// This security check can be bypassed by Prose components.
198-
if (dangerousTags.includes(renderTag)) {
198+
if (dangerousTags.includes(pascalCase(renderTag).toLowerCase())) {
199199
return h(
200200
'pre',
201201
{ class: 'mdc-renderer-dangerous-tag' },

0 commit comments

Comments
 (0)