🐛 Bug Fix
- GHSA-jhhp-r3r7-v2cg Security:
cleanHTML.removeEventAttributeswas not enforced by the background sanitizing pass —sanitizeHTMLElement()only strippedonerror, so any otheron*handler survived on markup that reached the editable area withoutsafeHTML, and a drop from another window was inserted by the browser natively, unsanitized, because the drop handler was only armed after adragstartseen in the same window. The background pass now strips everyon*attribute, and drops always go through the paste plugin's sanitizing path. Reported by David Vieira Kurz (HiSolutions AG).