diff --git a/lib/marked.js b/lib/marked.js index 9f1584bb3b..2696019cda 100644 --- a/lib/marked.js +++ b/lib/marked.js @@ -875,7 +875,7 @@ Renderer.prototype.link = function(href, title, text) { } catch (e) { return ''; } - if (prot.indexOf('javascript:') === 0 || prot.indexOf('vbscript:') === 0) { + if (prot.indexOf('javascript:') === 0 || prot.indexOf('vbscript:') === 0 || prot.indexOf('data:') === 0) { return ''; } } diff --git a/test/tests/links.sanitize.html b/test/tests/links.sanitize.html index 5a5a973589..58d6f5ea38 100644 --- a/test/tests/links.sanitize.html +++ b/test/tests/links.sanitize.html @@ -1,4 +1,5 @@

+

\ No newline at end of file diff --git a/test/tests/links.sanitize.text b/test/tests/links.sanitize.text index c2158fc82e..ba5d09fed7 100644 --- a/test/tests/links.sanitize.text +++ b/test/tests/links.sanitize.text @@ -4,4 +4,6 @@ [URL](javascript:alert(1)) -[URL](javascript:document;alert(1)) \ No newline at end of file +[URL](javascript:document;alert(1)) + +[URL](data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K) \ No newline at end of file