diff --git a/src/xss-filters.js b/src/xss-filters.js index 4f490d9..9a2de57 100644 --- a/src/xss-filters.js +++ b/src/xss-filters.js @@ -45,7 +45,7 @@ exports._getPrivFilters = function () { // Reference: http://shazzer.co.uk/database/All/Characters-after-javascript-uri // Reference: https://html.spec.whatwg.org/multipage/syntax.html#consume-a-character-reference // Reference for named characters: https://html.spec.whatwg.org/multipage/entities.json - var URI_BLACKLIST_PROTOCOLS = {'javascript':1, 'data':1, 'vbscript':1, 'mhtml':1}, + var URI_BLACKLIST_PROTOCOLS = {'javascript':1, 'data':1, 'vbscript':1, 'mhtml':1, 'x-schema':1}, URI_PROTOCOL_COLON = /(?::|&#[xX]0*3[aA];?|�*58;?|:)/, URI_PROTOCOL_WHITESPACES = /(?:^[\x00-\x20]+|[\t\n\r\x00]+)/g, URI_PROTOCOL_NAMED_REF_MAP = {Tab: '\t', NewLine: '\n'};