diff --git a/web/react/utils/markdown.jsx b/web/react/utils/markdown.jsx index 2b1aed9c063d..63ea3095d3e2 100644 --- a/web/react/utils/markdown.jsx +++ b/web/react/utils/markdown.jsx @@ -196,7 +196,7 @@ class MattermostMarkdownRenderer extends marked.Renderer { try { const unescaped = decodeURIComponent(unescape(href)).replace(/[^\w:]/g, '').toLowerCase(); - if (unescaped.indexOf('javascript:') === 0 || unescaped.indexOf('vbscript:') === 0) { // eslint-disable-line no-script-url + if (unescaped.indexOf('javascript:') === 0 || unescaped.indexOf('vbscript:') === 0 || unescaped.indexOf('data:') === 0) { // eslint-disable-line no-script-url return ''; } } catch (e) {