Skip to content

Document dangling markup injection - #45670

Closed
Gaalbu wants to merge 1 commit into
mdn:mainfrom
Gaalbu:docs/dangling-markup-injection
Closed

Gaalbu wants to merge 1 commit into
mdn:mainfrom
Gaalbu:docs/dangling-markup-injection

Conversation

@Gaalbu

@Gaalbu Gaalbu commented Sep 13, 2026

Copy link
Copy Markdown

Fixes #34727.

Add dangling markup injection to the web security attacks overview, including its mechanism and the relevant encoding and sanitization mitigation.

Source: https://portswigger.net/web-security/cross-site-scripting/dangling-markup

Signed-off-by: Gaalbu <gabrielalbuquerquealencar@gmail.com>
@Gaalbu
Gaalbu requested a review from a team as a code owner September 13, 2026 04:00
@Gaalbu
Gaalbu requested review from chrisdavidmills and removed request for a team September 13, 2026 04:00
@github-actions github-actions Bot added Content:Security Security docs size/xs [PR only] 0-5 LoC changed labels Sep 13, 2026
@Josh-Cena
Josh-Cena requested review from wbamberg and removed request for chrisdavidmills September 13, 2026 05:22
@Gaalbu

Gaalbu commented Sep 13, 2026

Copy link
Copy Markdown
Author

Friendly ping — this PR is ready for review whenever you have a chance.

@Josh-Cena

Josh-Cena commented Sep 13, 2026 •

Copy link
Copy Markdown
Member

Chill—it's a weekend and you pinged 14 hours after the PR was sent. We have 140 open PRs.

@Gaalbu

Gaalbu commented Sep 13, 2026

Copy link
Copy Markdown
Author

Got it, my bad :p. I'll chill and respect the queue. Appreciate the feedback!

@wbamberg wbamberg left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This isn't really documentation for a dangling markup attack. It doesn't really explain in a usable way what the attack is or how to protect against it, and it doesn't really integrate properly into the rest of the document.

Probably dangling markup should live in the XSS guide as it's quite closely related to that and the defenses are similar.

@wbamberg wbamberg closed this Sep 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Content:Security Security docs size/xs [PR only] 0-5 LoC changed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Document dangling markup injection

4 participants