Homestyx hydra

R1:54bcbdaba94a

Fix an XSS issue with certain high-priority remarkup rules embedded inside lower-priority link rules

Summary:
See <https://hackerone.com/reports/758002>. The link rules don't test that their parameters are flat text before using them in unsafe contexts.

Since almost all rules are lower-priority than these link rules, this behavior isn't obvious. However, two rules have broadly higher priority (monospaced text, and one variation of link rules has higher priority than the other), and the latter can be used…
Repository: R1 hydra
Commit Date: Dec 13 2019