react-doctor/react-markdown-unsanitized-raw-html
Unsanitized raw HTML in React Markdown
- Category: Security
- Severity: warn
- Source:
oxlint-plugin-react-doctor - Framework: global
- Enabled when: always
- Default: Enabled
Validate the diagnostic
Confirm the reported code matches this rule before you edit it.
Confirm the reported code matches react-doctor/react-markdown-unsanitized-raw-html. Compare it with the Before example and verify the same API, framework, and execution context. Treat it as a false positive only when one of those conditions differs.
Compare the code
The corrected pattern shows a focused way to address the diagnostic.
Reported pattern
import Markdown from "react-markdown";
import raw from "rehype-raw";
const Preview = ({ content }) => (
<Markdown rehypePlugins={[raw]}>{content}</Markdown>
);Corrected pattern
import Markdown from "react-markdown";
import raw from "rehype-raw";
import sanitize from "rehype-sanitize";
const Preview = ({ content }) => (
<Markdown rehypePlugins={[raw, sanitize]}>{content}</Markdown>
);How to fix
Use the corrected pattern as a reference. Preserve behavior that the rule does not require you to change.
Copyable fix prompt
Copy this self-contained prompt into your coding agent after you confirm the diagnostic.
Fix every confirmed
Reference transformation:Before:react-doctor/react-markdown-unsanitized-raw-html diagnostic in the current repository.
Required change:
- Add rehype-sanitize to rehypePlugins or sanitize dynamic markdown before rendering. skipHtml does not disable HTML already parsed by rehype-raw.import Markdown from "react-markdown";
import raw from "rehype-raw";
const Preview = ({ content }) => (
<Markdown rehypePlugins={[raw]}>{content}</Markdown>
);import Markdown from "react-markdown";
import raw from "rehype-raw";
import sanitize from "rehype-sanitize";
const Preview = ({ content }) => (
<Markdown rehypePlugins={[raw, sanitize]}>{content}</Markdown>
);Constraints:
- Confirm the reported code matches the Before pattern.
- Make the smallest change that fixes the root cause.
- Preserve behavior and interfaces unrelated to this diagnostic.
- Reuse existing project components, utilities, and conventions.
- Do not introduce render-phase side effects, render-phase state updates, or Hooks rule violations.
- Keep validation and authorization on trusted boundaries. Do not replace them with client-only checks.
- Adapt identifiers and framework details instead of copying blindly.
- Do not disable the rule or suppress matching code.
Verification:
- Run focused tests for the changed behavior.
- Run React Doctor and confirm this diagnostic no longer appears.
- Report the files changed and any checks you could not run.
Related rules
More Security rules from the rules reference:
react-doctor/react-router-csp-nonce-consistency: CSP nonce is not shared across server renderingreact-doctor/repository-secret-file: A committed env file, credential, or token is exposed to anyone with repo access and must be rotated, even after you remove it.react-doctor/request-body-mass-assignment: Request input spread without field allowlistreact-doctor/require-pnpm-hardening: pnpm project is missing supply-chain hardening in pnpm-workspace.yaml — set `minimumReleaseAge`, keep `blockExoticSubdeps: true`, and set `trustPolicy: no-downgrade`react-doctor/secret-in-fallback: Hardcoded secret fallback for env var