From a3453e31da629223e641398e872c38b109bb40ad Mon Sep 17 00:00:00 2001 From: edison Date: Tue, 21 Oct 2025 08:31:35 +0800 Subject: [PATCH] fix(runtime-vapor): setting innerHTML should go through trusted types (#14000) --- packages/runtime-vapor/src/dom/prop.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/packages/runtime-vapor/src/dom/prop.ts b/packages/runtime-vapor/src/dom/prop.ts index 9cd0f21491..b104b20900 100644 --- a/packages/runtime-vapor/src/dom/prop.ts +++ b/packages/runtime-vapor/src/dom/prop.ts @@ -381,7 +381,7 @@ export function setBlockHtml( block: Block & { $html?: string }, value: any, ): void { - value = value == null ? '' : value + value = value == null ? '' : unsafeToTrustedHTML(value) if (block.$html !== value) { setHtmlToBlock(block, (block.$html = value)) } -- 2.47.3