HTML Document Viewer treats every viewed document as hostile. A report that scripts execute, remote resources load, content reaches Obsidian's DOM, or a document escapes its iframe is security-sensitive and should not be disclosed in a public issue before a fix is available.
Use the private vulnerability reporting option in the Security tab of https://github.com/initialcapacity/obsidian-html-viewer. Include the Obsidian version, platform, minimal fixture, expected result, and observed result. Remove all real vault content, credentials, tokens, and personal information.
Use GitHub Issues only for non-sensitive defects and feature requests.