waylonflinn/markdown-it-katex

another XSS

Opened this issue · 0 comments

oelin commented

\unicode{} also allows for XSS

$\unicode{<img src=x onerror=alert(1)>}$