You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

sanitize-html的allowedSchemes配置不生效,file scheme未被拦截

sanitize-html未拦截meta refresh属性中的file协议问题

代码示例

var sanitizeHtml = require("sanitize-html");

const ALLOWED_SCHEMES = ['http', 'https'];

const htmlStr = '\'"><meta http-equiv="refresh" content="0;url=file:///etc/passwd" />';

const cleanedHTML = sanitizeHtml(htmlStr, {
    allowedAttributes: false,
    allowedTags: false,
    allowVulnerableTags: true,
    allowedSchemes: ALLOWED_SCHEMES,
    allowProtocolRelative: false,
    disallowedTagsMode: 'completelyDiscard',
    allowedSchemesByTag: {
        img: [...ALLOWED_SCHEMES, 'data']
    },
});

console.log(cleanedHTML);

实际输出

'"><meta http-equiv="refresh" content="0;url=file:///etc/passwd" />'

预期输出

'"><meta http-equiv="refresh" content="0" />'

问题说明

尽管已配置仅允许http和https协议,但meta标签的content="0;url=file:///etc/passwd"属性中包含的file协议并未被拦截,仍然保留在输出结果中。

环境细节

  • Node.js版本:18 LTS
  • sanitize-html版本:2.13.1

内容的提问来源于stack exchange,提问作者adarsh srivastava

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 08:08:23