-
-
Notifications
You must be signed in to change notification settings - Fork 65
Open
Description
Describe the bug
JavaScript and external resources are allowed in "HTML version" of email which might lead to tracking and IP address leakage, and other wide range of security issues.
To Reproduce
Steps to reproduce the behavior:
- Send urself an HTML with inline javascript." <script>alert(1)</script>
- In bot click on "View HTML"
Expected behavior
By default they should be blocked OR at least user should be given control.
Metadata
Metadata
Assignees
Labels
No labels