diff --git a/site/content/docs/02-template-syntax.md b/site/content/docs/02-template-syntax.md index 600634ab11..d9b1345fec 100644 --- a/site/content/docs/02-template-syntax.md +++ b/site/content/docs/02-template-syntax.md @@ -318,10 +318,12 @@ If you don't care about the pending state, you can also omit the initial block. --- -In a text expression, characters like `<` and `>` are escaped. With HTML expressions, they're not. +In a text expression, characters like `<` and `>` are escaped; however, with HTML expressions, they're not. > Svelte does not sanitize expressions before injecting HTML. If the data comes from an untrusted source, you must sanitize it, or you are exposing your users to an XSS vulnerability. +> Due to the limitations of the DOM APIs available to insert raw HTML fragments, this directive cannot be used to surround content with additional markup. + ```html

{post.title}