mirror of
https://github.com/9001/copyparty.git
synced 2026-01-08 04:25:56 +10:00
by running dompurify after marked.parse if plugins are not enabled; adds no protection against the more practical approach of just putting a malicious <script> in an html file and uploading that, but one footgun less is one less footgun