codsen / codsen

a monorepo of npm packages

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

string-strip-html

revelt opened this issue · comments

Package's name
string-strip-html

Describe the bug
Investigate input string H4<bE77]7oQL

CC @mherger

I decided not to fix, the pattern causes browser's parser to patch it
Screenshot 2021-09-28 at 08 59 56
such things can be attack vectors. Having said that, I'll implement the opts.stripRecognisedHTMLOnly see #23 so whoever wants strict mild stripping will be able to "tone down" the harshness.