syncfusion-aspnetcore-rich-text-editor
Audited by Socket on Sep 22, 2026
3 alerts found:
Anomalyx2SecurityThis is primarily benign Rich Text Editor API documentation and example code. The identity sanitizer callback is a significant insecure configuration because it can bypass HTML sanitization and enable XSS if used in production. The upload response is also trusted for DOM URL assignment without validation. These are application security concerns, not evidence of intentional malicious supply-chain behavior.
The fragment is documentation with no clear malicious behavior or obfuscation. However, the SaveImage sample is insecure if used unchanged: it trusts an uploaded filename for a filesystem path, writes into the web root, lacks visible authorization and server-side validation, and may permit path traversal or unsafe public file upload depending on deployment. FileManager endpoints and rich-text URL content also require independent authorization and sanitization. Malware is not indicated, but the sample warrants security remediation before production use.
The fragment is legitimate Markdown editor documentation and shows no evidence of intentional malware. However, the live preview has a significant potential XSS risk because Marked.js output is inserted into innerHTML without sanitization. The old CDN-hosted Marked.js version and lack of integrity protection add dependency and supply-chain risk. Sanitize rendered HTML with a maintained sanitizer, validate URL schemes, use a current Marked.js release, and consider Subresource Integrity or self-hosting.