Merge pull request from GHSA-g6w6-7xf9-m95p

Don't store mermaid diagrams in innerHTML
This commit is contained in:
David Mehren 2020-12-27 19:49:57 +01:00 committed by GitHub
commit 58276ebbf4
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -386,7 +386,7 @@ export function finishView (view) {
window.mermaid.mermaidAPI.parse($value.text())
$ele.addClass('mermaid')
$ele.html($value.text())
$ele.text($value.text())
window.mermaid.init(undefined, $ele)
} catch (err) {
var errormessage = err