Skip to content

Commit d6cb57c

Browse files
authored
Fix innerHTML cause RCE security issue (#19)
Fix innerHTML cause RCE security issue
2 parents 44117d1 + 4a14092 commit d6cb57c

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

renderer.js

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -57,8 +57,8 @@ window.onload = () => {
5757

5858
webview.addEventListener('dom-ready', function () {
5959
// set webview title
60-
document.querySelector('#navbar-container .title').innerHTML = webview.getTitle()
61-
document.querySelector('title').innerHTML = webview.getTitle()
60+
document.querySelector('#navbar-container .title').innerText = webview.getTitle()
61+
document.querySelector('title').innerText = webview.getTitle()
6262

6363
// set dark theme if in home page
6464
if (webview.getURL().split('?')[0].split('#')[0].match(/https?:\/\/hackmd.io\/$/)) {

0 commit comments

Comments
 (0)