From 87501a1bdd4824a1f3d298ad4d62c3b72c4f7e92 Mon Sep 17 00:00:00 2001 From: Daniel <845765@qq.com> Date: Sat, 12 Jul 2025 11:13:25 +0800 Subject: [PATCH] :lock: XSS in inline-memo https://github.com/siyuan-note/siyuan/issues/15280 --- app/src/protyle/util/onGet.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/src/protyle/util/onGet.ts b/app/src/protyle/util/onGet.ts index 0f94e040f..2b998e181 100644 --- a/app/src/protyle/util/onGet.ts +++ b/app/src/protyle/util/onGet.ts @@ -135,7 +135,7 @@ const setHTML = (options: { } if (DOMPurify) { - // XSS in inline-memo https://github.com/siyuan-note/siyuan/issues/15280 + // XSS in inline memo elements https://github.com/siyuan-note/siyuan/issues/15280 const parser = new DOMParser(); const doc = parser.parseFromString(options.content, "text/html"); doc.querySelectorAll("[data-inline-memo-content]").forEach(item => {