When markdown is being presented as HTML, there seems to be a strange interaction between _ and @ that lets an attacker insert malicious tags. # Proof of Concept : ``` hello ``` is rendered converted to the following HTML: ``` /http:hello ``` As you can see, the output...
{{#tags}}- {{label}}
{{/tags}}