Skip to content

Document that serde_json doesn't escape forward slashes #537

Open
@LunaBorowska

Description

@LunaBorowska

An user should manually escape the slash (for instance using #435 (comment)) when putting JSON inside of <script> (yes, people do that), otherwise an XSS will occur. This ideally would be documented, as it is a potential security vulnerability.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions