The comrak we were matching unsafe URL prefixes, such as data: or javascript: , in a case-sensitive manner. This meant prefixes like Data: were untouched.
data:
javascript:
Data:
{ "license": "CC0-1.0" }
{ "affects": { "arch": [], "functions": [], "os": [] }, "affected_functions": null }
{ "categories": [ "format-injection" ], "informational": null, "cvss": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" }