diff --git a/lib/default.js b/lib/default.js index 1452ed3..55c506c 100644 --- a/lib/default.js +++ b/lib/default.js @@ -159,6 +159,10 @@ function safeAttrValue(tag, name, value, cssFilter) { value.substr(0, 8) === "https://" || value.substr(0, 7) === "mailto:" || value.substr(0, 4) === "tel:" || + value.substr(0, 11) === "data:image/" || + value.substr(0, 6) === "ftp://" || + value.substr(0, 2) === "./" || + value.substr(0, 3) === "../" || value[0] === "#" || value[0] === "/" )