mirror of
https://github.com/9001/copyparty.git
synced 2026-09-24 22:03:42 +01:00
by running dompurify after marked.parse if plugins are not enabled; adds no protection against the more practical approach of just putting a malicious <script> in an html file and uploading that, but one footgun less is one less footgun