syncfusion-vue-rich-text-editor

Warn

Audited by Socket on Sep 22, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/editor-modes.md

The fragment documents a legitimate rich-text and Markdown preview integration. It contains no evidence of malware or supply-chain sabotage. The direct insertion of `marked.parse` output into `innerHTML` is a security risk when editor content is attacker-controlled; rendered output should be sanitized and appropriate URL and HTML restrictions should be applied before insertion.

Confidence: 98%Severity: 62%
AnomalyLOW
references/validation-security.md

The fragment is documentation and configuration examples, not malware. The main security concern is the custom sanitizer example: it disables the built-in sanitizer and performs incomplete script removal, which could permit XSS if used with untrusted HTML. The unrestricted HTTPS iframe rule is also a security and privacy concern. Default sanitizer behavior is less risky, but server-side sanitization remains appropriate for persisted or user-generated HTML.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Sep 22, 2026, 12:56 PM
Package URL
pkg:socket/skills-sh/syncfusion%2Fvue-ui-components-skills%2Fsyncfusion-vue-rich-text-editor%2F@e79cab912fd0cb1fc0d6dbbb1c323656159bd4fe01d82e1d4636551a6a26f884
Security Audit — socket — syncfusion-vue-rich-text-editor