Skip to content

Important security consideration for using target="_blank" #413

@stackola

Description

@stackola

Using target="_blank" on hyperlinks without using rel="noopener" is a problem, because the opened page can access and modify some properties on the opening page.

You can find out more information here:

https://www.jitbit.com/alexblog/256-targetblank---the-most-underestimated-vulnerability-ever/

Proposed fix

Automatically add rel="noopener noreferrer" to all links that are targeting _blank, or make rel user-accessible like target

Metadata

Metadata

Assignees

No one assigned

    Labels

    👀 no/externalThis makes more sense somewhere else

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions