# Can I embed HTML code in Kibana?

**URL:** <https://discuss.elastic.co/t/can-i-embed-html-code-in-kibana/94060>\
**Category:** Kibana\
**Created:** [July 21, 2017, 6:18am UTC](https://discuss.elastic.co/t/can-i-embed-html-code-in-kibana/94060 "2017-07-21T06:18:45Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Helix](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/helix/32/19987_2.png) [@Helix](https://discuss.elastic.co/u/Helix)\
**Post date:** [July 21, 2017, 6:18am UTC](https://discuss.elastic.co/t/can-i-embed-html-code-in-kibana/94060/1 "2017-07-21T06:18:45Z")

</div>

Hello,

I found a Blog Post describing how to embed HTML code in Kibana Version 4 [here](http://www.supermind.org/blog/1213/embed-custom-javascript-and-html-in-a-kibana-4-x-visualization). Is this still possible in Kibana 5 or is there a different way to do it now?

Thank you in advance!

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [July 21, 2017, 2:25pm UTC](https://discuss.elastic.co/t/can-i-embed-html-code-in-kibana/94060/2 "2017-07-21T14:25:08Z")

</div>

Hi Helix,

thanks for your question. Actually it is still not possible without modifying source code (mainly for security reasons).

Also the source code you would have do modify looks a little bit different now. For version 5.5.0 you can find the relevant source code file at [markdown\_vis\_controller on GitHub](https://github.com/elastic/kibana/blob/v5.5.0/src/core_plugins/markdown_vis/public/markdown_vis_controller.js)

What would you need to change?

1. Change in line 7, the `sanitize: true` to `sanitize: false`.
2. Add in line 12 `$sce` to the function parameters (to get the $sce service of Angular (responsible for securing HTML) injected into the controller)
3. Modify line 15 to use the serice as follows: `$scope.html = $sce.trustAsHtml(marked(html));`

**Be aware that this introduces a high security vulnerability to your Kibana!** Anyone can now save visualizations that can contain `script` tags and execute JavaScript in the browser of other users.

If you just want to add some "safe" HTML tags (like `a`, `span`, `b`, etc.) just make modification **1** from the list above and skip 2 and 3. That way Angular will still sanitize your input.

Also be aware that making modifications to Kibana might cause you quite some work, when upgrading your versions, i.e. if you look at the mentioned file on GitHub you can see, that it already changed since version 5.5.0, so you would need to repeat your modifications for the next versions.

Cheers,  
Tim

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 18, 2017, 2:36pm UTC](https://discuss.elastic.co/t/can-i-embed-html-code-in-kibana/94060/3 "2017-08-18T14:36:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
