github cure53/DOMPurify 2.2.0
DOMPurify 2.2.0

latest releases: 3.1.7, 2.5.7, 3.1.6...
3 years ago
  • Fix a possible XSS in Chrome that is hidden behind #enable-experimental-web-platform-features, reported by @neilj and @mfreed7
  • Changed RETURN_DOM_IMPORT default to true to address said possible XSS
  • Updated README to reflect the new change and inform about the risks of manually setting RETURN_DOM_IMPORT back to false
  • Fixed the tests to properly address the new default

Don't miss a new DOMPurify release

NewReleases is sending notifications on new releases.