Untrusted content
Edit on GitHubWhat's safe to render, and how to handle MDX you didn't write.
MDX can contain JavaScript, and that code runs when the page renders. Files in your own repository are fine. MDX from a CMS, a database or your users needs more care.
Always on
- Slugs can't leave the content folder. Slugs often come from the URL, so
../../etc/passwdis rejected. - JavaScript frontmatter (
---js) is refused. - MDX
importandexportstatements are switched off. - An invalid
_meta.jsonthrows instead of silently changing the sidebar.
Blocking JavaScript
For MDX you don't trust, set blockJs:
const { MDX } = await parseMdx({ source: await cms.getPage(id), blockJs: true });
This removes {expressions}, import/export lines and attributes like onClick={...} before compiling. Markdown and JSX tags with plain string attributes still work.
The components you pass in still run. Don't give untrusted MDX a component that renders raw HTML from its props.