npm dompurify 2.0.2
DOMPurify 2.0.2

latest releases: 3.2.6, 3.2.5, 3.2.4...
5 years ago

Following the release of DOMPurify 2.0.1, a more thorough internal audit against Blink-based mXSS bugs was conducted. Several mXSS variations, spotted by @masatokinugawa were addressed and fixed. The fixes were reviewed and so far no new bypasses could be spotted.

This release manages to find what is believed to be a more holistic way to prevent mXSS bugs, specifically coming from HTML attributes and tags nested inside SVG and MathML.

Further, this release also addresses a DoS problem caused by sanitization of HTML tables when configured with potentially conflicting configuration settings.

Don't miss a new dompurify release

NewReleases is sending notifications on new releases.