github cure53/DOMPurify 2.0.3
DOMPurify 2.0.3

latest releases: 3.1.1, 2.5.1, 3.1.0...
4 years ago
  • Fixed another mXSS variation affecting Chrome, Safari and Edge relating to HTML templates
  • Fixed a bug in the config parser leading to unexpected results

Credits for the bypass again go to Michał Bentkowski (@securityMB) of Securitum who spotted the bug in Chrome, turned it into another DOMPurify bypass, reported and helped verifying the fix 🙇‍♂️ 🙇‍♀️

Don't miss a new DOMPurify release

NewReleases is sending notifications on new releases.