Security
This page gathers the behaviors that matter when handling untrusted Markdown: HTML passthrough, outbound requests, and third-party script sources.
HTML Is Not Sanitized
transToHTML() does not sanitize. HTML tags and attributes in the text are kept as-is, and MDViewer writes the result into the page through innerHTML:
<img src=x onerror="alert(document.cookie)">
This runs directly in the viewer. Only text inside inline code and code blocks is escaped.
| Situation | Risk | Recommendation |
|---|---|---|
| Users editing their own content | Low: affects only themselves | Use as-is |
| Previewing Markdown submitted by others | High: stored XSS | Do not display it with MDViewer; convert with MDParser, sanitize with a tool such as DOMPurify, then insert |
| Converting on a server before publishing | High | Same as above; sanitize before storing |
MDViewer offers no hook to intercept HTML before it is written, so the viewer is only suitable for trusted content.
Links
Every link is target="_blank" with no rel. Current mainstream browsers apply noopener to _blank by default, but in older browsers the opened page can still rewrite the original through window.opener.
Outbound Requests
| Trigger | Destination | Note |
|---|---|---|
| Bundle load | jsDelivr, Google Fonts | See Runtime Dependencies |
| Content with a YouTube link | i.ytimg.com |
Thumbnail loads; the iframe loads only after a click |
| Content with a Vimeo link | vimeo.com/api/v2 |
Synchronous XHR for the thumbnail on every conversion |
| Content with external images/video | The image host | Loaded on preview; can be used to track a reader's IP |
| Deploy button | nanomd-deploy.pardn.workers.dev |
Appears only on nanomd.pardn.io; uploads the content |
Third-party Script Versions
code-prettify is loaded from gh/google/code-prettify@master, a moving branch rather than a pinned version, and without Subresource Integrity. Where supply-chain guarantees matter, self-host code-prettify and Mermaid and put window.PR and window.mermaid in place before NanoMD loads.
Exported HTML
Files produced by download("html") contain the same unsanitized raw HTML and load run_prettify.js from jsDelivr. Check where the content came from before sharing an export.