Vue · Security
vite-doctor/vuesecurityerrorSuggestion
Why it happens
Untrusted HTML and scripts are high-risk rendering surfaces. Keep them explicit, constrained, and routed through framework APIs that encode intent.
Fix
Keep v HTML behind the safest Vue API available for that surface.
Example
Sanitize v-html input
Before
<template>
<div v-html="comment.body" />
</template>
After
<template>
<div v-html="sanitizeHtml(comment.body)" />
</template>
Verify the fix
Run only this rule after editing so the report stays focused on the diagnostic you are closing:
pnpm vite-doctor . --framework vue --rules vue/security/restrict-v-html