syncfusion-vue-rich-text-editor
Audited by Socket on Sep 22, 2026
2 alerts found:
Anomalyx2The fragment documents a legitimate rich-text and Markdown preview integration. It contains no evidence of malware or supply-chain sabotage. The direct insertion of `marked.parse` output into `innerHTML` is a security risk when editor content is attacker-controlled; rendered output should be sanitized and appropriate URL and HTML restrictions should be applied before insertion.
The fragment is documentation and configuration examples, not malware. The main security concern is the custom sanitizer example: it disables the built-in sanitizer and performs incomplete script removal, which could permit XSS if used with untrusted HTML. The unrestricted HTTPS iframe rule is also a security and privacy concern. Default sanitizer behavior is less risky, but server-side sanitization remains appropriate for persisted or user-generated HTML.