syncfusion-angular-blockeditor

Warn

Audited by Snyk on Mar 25, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill's docs and workflows show the editor ingesting and rendering untrusted external content (e.g., importFromClipboard / importFromHtml and parseHtmlToBlocks in references/data-export-and-import.md, image/avatar src URLs and remote saveUrl in references/advanced-features.md, and preview.innerHTML/getDataAsHtml usage) and explicitly allow disabling HTML encoding (references/configuration-properties.md), so third‑party/user-provided HTML or URLs could be parsed and rendered and thus influence behavior beyond simple display.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 25, 2026, 04:41 PM
Issues
1