HtmlSanitizer icon indicating copy to clipboard operation
HtmlSanitizer copied to clipboard

Sanitizer does not handle certain html string

Open deepakageeru opened this issue 7 months ago • 1 comments

var sanitizer = new HtmlSanitizer(); var html = @"<<img>svg onload=alert(document.domain)>"; var sanitized = sanitizer.Sanitize(html, "http://www.example.com"); Console.WriteLine(sanitized); // returns "&lt;<img>svg onload=alert(document.domain)&gt;"

Image

deepakageeru avatar Jun 04 '25 21:06 deepakageeru

Looks fine to me at first glance. What output do you expect?

mganss avatar Jun 05 '25 07:06 mganss