The comrak we were matching unsafe URL prefixes, such as data: or javascript: , in a case-sensitive manner. This meant prefixes like Data: were untouched.
data:
javascript:
Data:
{ "license": "CC0-1.0" }
{ "affected_functions": null, "affects": { "arch": [], "os": [], "functions": [] } }
[ "format-injection" ]
"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
null
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2021-0026.json"