Vue · VUE0009

Restrict v-html to trusted HTML

Flags risky v HTML usage in Vue security code.
VUE0009vite-doctor/vuesecurityerrorSuggestion

Run this rule

pnpm vite-doctor . --framework vue --rules vue/security/restrict-v-html

Why it matters

Untrusted HTML and scripts are high-risk rendering surfaces. Keep them explicit, constrained, and routed through framework APIs that encode intent.

Keep v HTML behind the safest Vue API available for that surface.

Example

Sanitize v-html input

Before

<template>
  <div v-html="comment.body" />
</template>

After

<template>
  <div v-html="sanitizeHtml(comment.body)" />
</template>
Copyright © 2026