github cure53/DOMPurify 2.0.4
DOMPurify 2.0.4

latest releases: 3.1.3, 2.5.3, 3.1.2...
4 years ago

Another mXSS variation was spotted by @masatokinugawa and got addressed and fixed in this release.

The fixes were reviewed and no new bypasses could be spotted at the moment.
Thanks, @masatokinugawa 🙇‍♂️ 🙇‍♀️!

The sanitization logic for this kind of mXSS was changed to be less aggressive and still be able to spot all recent mXSS variations we know about right now - while also avoiding risky string matching.

Prayers and thoughts that this was the final variation. But better be on the lookout for more releases soon.

Don't miss a new DOMPurify release

NewReleases is sending notifications on new releases.