Encoded javascript: protocol bypassEMBEDDED

Check whether HTML entities, control characters, or casing variations bypass javascript: URL validation.

HTML payload check

This scenario tests how user input is rendered into HTML / DOM, not iframe sandbox behavior.

  • Decode entities and strip control characters before validating URL attributes
  • Validate against a protocol allowlist such as http, https, and mailto
  • Verify that renderers and sanitizers use the same normalization rules

Payload

Payload to copy

Checks whether protocol validation happens after attribute decoding.

Paste into

An editor, comment, profile, or HTML-rendering input in a dev/staging surface you are authorized to test

Result rule

Execution is a warning sign. Expected defenses render the code as text or remove the executable parts.

Preview

The preview intentionally performs unsafe rendering for learning. In a real service, this payload should be escaped as text or removed.

Log

// no logs

Explanation