New
Introducing React Bench, see how different models perform on React code

react-doctor/react-markdown-unsanitized-raw-html

Unsanitized raw HTML in React Markdown

  • Category: Security
  • Severity: warn
  • Source: oxlint-plugin-react-doctor
  • Framework: global
  • Enabled when: always
  • Default: Enabled

Validate the diagnostic

Confirm the reported code matches this rule before you edit it.

Confirm the reported code matches react-doctor/react-markdown-unsanitized-raw-html. Compare it with the Before example and verify the same API, framework, and execution context. Treat it as a false positive only when one of those conditions differs.

Compare the code

The corrected pattern shows a focused way to address the diagnostic.

Reported pattern

import Markdown from "react-markdown";
import raw from "rehype-raw";
const Preview = ({ content }) => (
  <Markdown rehypePlugins={[raw]}>{content}</Markdown>
);

Corrected pattern

import Markdown from "react-markdown";
import raw from "rehype-raw";
import sanitize from "rehype-sanitize";
const Preview = ({ content }) => (
  <Markdown rehypePlugins={[raw, sanitize]}>{content}</Markdown>
);

How to fix

Use the corrected pattern as a reference. Preserve behavior that the rule does not require you to change.

Copyable fix prompt

Copy this self-contained prompt into your coding agent after you confirm the diagnostic.

Fix every confirmed react-doctor/react-markdown-unsanitized-raw-html diagnostic in the current repository. Required change: - Add rehype-sanitize to rehypePlugins or sanitize dynamic markdown before rendering. skipHtml does not disable HTML already parsed by rehype-raw.
Reference transformation:Before:
import Markdown from "react-markdown";
import raw from "rehype-raw";
const Preview = ({ content }) => (
  <Markdown rehypePlugins={[raw]}>{content}</Markdown>
);
After:
import Markdown from "react-markdown";
import raw from "rehype-raw";
import sanitize from "rehype-sanitize";
const Preview = ({ content }) => (
  <Markdown rehypePlugins={[raw, sanitize]}>{content}</Markdown>
);
Constraints: - Confirm the reported code matches the Before pattern. - Make the smallest change that fixes the root cause. - Preserve behavior and interfaces unrelated to this diagnostic. - Reuse existing project components, utilities, and conventions. - Do not introduce render-phase side effects, render-phase state updates, or Hooks rule violations. - Keep validation and authorization on trusted boundaries. Do not replace them with client-only checks. - Adapt identifiers and framework details instead of copying blindly. - Do not disable the rule or suppress matching code. Verification: - Run focused tests for the changed behavior. - Run React Doctor and confirm this diagnostic no longer appears. - Report the files changed and any checks you could not run.

More Security rules from the rules reference: