github cure53/DOMPurify 2.0.16
DOMPurify 2.0.16

latest releases: 3.2.0, 3.1.7, 2.5.7...
4 years ago
  • Fixed an mXSS-based bypass caused by nested forms inside MathML
  • Fixed a security error thrown on older Chrome on Android versions, see #470

Credits for the bypass go to Michał Bentkowski (@securityMB) of Securitum who spotted the bug in Chrome, turned it into another DOMPurify bypass, reported and helped verifying the fix 🙇‍♂️ 🙇‍♀️

Don't miss a new DOMPurify release

NewReleases is sending notifications on new releases.