sanitize-html的allowedSchemes配置不生效,file scheme未被拦截
sanitize-html未拦截meta refresh属性中的file协议问题
代码示例
var sanitizeHtml = require("sanitize-html"); const ALLOWED_SCHEMES = ['http', 'https']; const htmlStr = '\'"><meta http-equiv="refresh" content="0;url=file:///etc/passwd" />'; const cleanedHTML = sanitizeHtml(htmlStr, { allowedAttributes: false, allowedTags: false, allowVulnerableTags: true, allowedSchemes: ALLOWED_SCHEMES, allowProtocolRelative: false, disallowedTagsMode: 'completelyDiscard', allowedSchemesByTag: { img: [...ALLOWED_SCHEMES, 'data'] }, }); console.log(cleanedHTML);
实际输出
'"&gt;<meta http-equiv="refresh" content="0;url=file:///etc/passwd" />'
预期输出
'"&gt;<meta http-equiv="refresh" content="0" />'
问题说明
尽管已配置仅允许http和https协议,但meta标签的content="0;url=file:///etc/passwd"属性中包含的file协议并未被拦截,仍然保留在输出结果中。
环境细节
- Node.js版本:18 LTS
- sanitize-html版本:2.13.1
内容的提问来源于stack exchange,提问作者adarsh srivastava
相关产品推荐
相关产品推荐

