diff --git a/src/index.ts b/src/index.ts index 9523035..086caf8 100644 --- a/src/index.ts +++ b/src/index.ts @@ -86,7 +86,7 @@ function setupOpenSelfInNewTabLink() { */ function isValidSuspectHref(href: string) { /* eslint-disable-next-line */ - const disallowedProtocols = ['javascript:']; + const disallowedProtocols = ['javascript:', 'data:', 'vbscript:']; const parsedSuspectHref = new URL(href); return disallowedProtocols.indexOf(parsedSuspectHref.protocol) < 0;