Skip to content

Conversation

@th0r
Copy link
Collaborator

@th0r th0r commented Apr 11, 2019

Don't let </script> in chartData or in internal assets break the page.

Vulnerability details: https://blog.uploadcare.com/vulnerability-in-html-design-the-script-tag-33d24642359e

@th0r th0r merged commit 3ce1b8c into master Apr 11, 2019
@th0r th0r deleted the proper-js-escape branch April 11, 2019 10:55
@valscion
Copy link
Member

This seems to have caused a regression, see #263

This was referenced Mar 11, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

3 participants