Vue · VUE0009
Restrict v-html to trusted HTML
Flags risky v HTML usage in Vue security code.
Run this rule
pnpm vite-doctor . --framework vue --rules vue/security/restrict-v-html
Why it matters
Untrusted HTML and scripts are high-risk rendering surfaces. Keep them explicit, constrained, and routed through framework APIs that encode intent.
Recommended fix
Keep v HTML behind the safest Vue API available for that surface.
Useful links
Example
Sanitize v-html input
Before
<template>
<div v-html="comment.body" />
</template>
After
<template>
<div v-html="sanitizeHtml(comment.body)" />
</template>