github naver/egjs-flicking 4.17.1
4.17.1 Release (2026-09-30)

3 hours ago

Packages

Package Version
@egjs/flicking 4.17.1
@egjs/react-flicking 4.17.1
@egjs/vue3-flicking 4.17.1

Highlights

  • Fixed a mutation-XSS (mXSS) vulnerability in panel serialization — CrossFlicking and Flicking#setStatus used to round-trip panel content through innerHTML/outerHTML strings, which could revive a payload that was inert on first render. CrossFlicking now builds its structure only through cloneNode/appendChild, and setStatus parses the stored html inertly and strips script-capable content (<script>, <iframe>, on* handlers, javascript: URLs) before restoring panels. Upgrading is recommended for every app that calls setStatus with untrusted content or uses CrossFlicking. (#960)
  • React Strict Mode compatibility via dependency updates — @egjs/axes is bumped to ^3.9.3 and @egjs/react-flicking now depends on @cfcs/react ^0.1.1, picking up the fixes needed to run cleanly under React Strict Mode's double-invocation. (#963)

Note: setStatus now sanitizes the html it restores. If you relied on restoring panels that contain inline event handlers or script-capable elements through setStatus, those attributes/elements are stripped as of this version.

What's Changed

  • chore: node 삭제, react strict mode 대응한 모듈 업데이트 by @daybrush in #963
  • feat(release): 머지 후 publish 순서 도입 & /release 스킬 추가 by @cjw783 in #961
  • fix(release): bump 인자 제거, 3단계 버전 확인 상시화 by @cjw783 in #967
  • fix: use cloneNode instead of innerHTML by @malangfox in #960

Full Changelog: 4.17.0...4.17.1

Don't miss a new egjs-flicking release

NewReleases is sending notifications on new releases.