Documentation 1.11.6

Security

This page gathers the behaviors that matter when handling untrusted Markdown: HTML passthrough, outbound requests, and third-party script sources.

HTML Is Not Sanitized

transToHTML() does not sanitize. HTML tags and attributes in the text are kept as-is, and MDViewer writes the result into the page through innerHTML:

<img src=x onerror="alert(document.cookie)">

This runs directly in the viewer. Only text inside inline code and code blocks is escaped.

Situation Risk Recommendation
Users editing their own content Low: affects only themselves Use as-is
Previewing Markdown submitted by others High: stored XSS Do not display it with MDViewer; convert with MDParser, sanitize with a tool such as DOMPurify, then insert
Converting on a server before publishing High Same as above; sanitize before storing

MDViewer offers no hook to intercept HTML before it is written, so the viewer is only suitable for trusted content.

Every link is target="_blank" with no rel. Current mainstream browsers apply noopener to _blank by default, but in older browsers the opened page can still rewrite the original through window.opener.

Outbound Requests

Trigger Destination Note
Bundle load jsDelivr, Google Fonts See Runtime Dependencies
Content with a YouTube link i.ytimg.com Thumbnail loads; the iframe loads only after a click
Content with a Vimeo link vimeo.com/api/v2 Synchronous XHR for the thumbnail on every conversion
Content with external images/video The image host Loaded on preview; can be used to track a reader's IP
Deploy button nanomd-deploy.pardn.workers.dev Appears only on nanomd.pardn.io; uploads the content

Third-party Script Versions

code-prettify is loaded from gh/google/code-prettify@master, a moving branch rather than a pinned version, and without Subresource Integrity. Where supply-chain guarantees matter, self-host code-prettify and Mermaid and put window.PR and window.mermaid in place before NanoMD loads.

Exported HTML

Files produced by download("html") contain the same unsanitized raw HTML and load run_prettify.js from jsDelivr. Check where the content came from before sharing an export.

中文