Skip to content

Commit ca4d56c

Browse files
committed
[FIX] RDSC-67 XSS exploit
1 parent e2fd1fa commit ca4d56c

1 file changed

Lines changed: 3 additions & 1 deletion

File tree

lib/mail-parser.js

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1120,7 +1120,9 @@ class MailParser extends Transform {
11201120
result.push(textPart);
11211121
}
11221122

1123-
result.push(`<a href="${link.url}">${link.text}</a>`);
1123+
result.push(
1124+
`<a href="${he.encode(link.url, { useNamedReferences: true })}">${he.encode(link.text, { useNamedReferences: true })}</a>`
1125+
);
11241126

11251127
last = link.lastIndex;
11261128
});

0 commit comments

Comments
 (0)