Skip to content

Remove [[ link syntax from C# XSS sink#22095

Draft
d10c wants to merge 1 commit into
github:mainfrom
d10c:d10c/drop-bracket-style-links
Draft

Remove [[ link syntax from C# XSS sink#22095
d10c wants to merge 1 commit into
github:mainfrom
d10c:d10c/drop-bracket-style-links

Conversation

@d10c

@d10c d10c commented Jun 30, 2026

Copy link
Copy Markdown
Contributor

Remove the makeUrl() private predicate and [[ usage from AspxCodeSink.explanation() in XSSSinks.qll, replacing it with plain text. This syntax is legacy and undocumented.

Remove the makeUrl predicate and the [[""|""]]] link syntax from
AspxCodeSink.explanation(), replacing with plain text.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions github-actions Bot added the C# label Jun 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant