From 1ff179a1bde88fd20f8956871d367c7d490ec160 Mon Sep 17 00:00:00 2001 From: amedora Date: Fri, 24 May 2019 15:55:05 +0900 Subject: [PATCH] fix mermaid xss --- browser/components/MarkdownPreview.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/browser/components/MarkdownPreview.js b/browser/components/MarkdownPreview.js index 55b36243b..17b13a513 100755 --- a/browser/components/MarkdownPreview.js +++ b/browser/components/MarkdownPreview.js @@ -845,7 +845,7 @@ export default class MarkdownPreview extends React.Component { _.forEach( this.refs.root.contentWindow.document.querySelectorAll('.mermaid'), el => { - mermaidRender(el, htmlTextHelper.decodeEntities(el.innerHTML), theme) + mermaidRender(el, htmlTextHelper.encodeEntities(el.innerHTML), theme) } )