-
-
Notifications
You must be signed in to change notification settings - Fork 922
Closed
Labels
👀 no/externalThis makes more sense somewhere elseThis makes more sense somewhere else
Description
Using target="_blank" on hyperlinks without using rel="noopener" is a problem, because the opened page can access and modify some properties on the opening page.
You can find out more information here:
https://www.jitbit.com/alexblog/256-targetblank---the-most-underestimated-vulnerability-ever/
Proposed fix
Automatically add rel="noopener noreferrer" to all links that are targeting _blank, or make rel user-accessible like target
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
👀 no/externalThis makes more sense somewhere elseThis makes more sense somewhere else