disallow use of v-html to prevent XSS attack

  • ⚙️ This rule is included in all of "plugin:vue/vue3-recommended", *.configs["flat/recommended"], "plugin:vue/recommended" and *.configs["flat/vue2-recommended"].

📖 Rule Details

This rule reports all uses of v-html directive in order to reduce the risk of injecting potentially unsafe / unescaped html into the browser leading to Cross-Site Scripting (XSS) attacks.

🔧 Options


🔇 When Not To Use It

If you are certain the content passed to v-html is sanitized HTML you can disable this rule.

🚀 Version

This rule was introduced in eslint-plugin-vue v4.7.0

🔍 Implementation