npm hugerte 1.0.12
v1.0.12

10 hours ago

Fixed

  • Security: Upgraded DOMPurify from 3.4.0 to 3.4.11, fixing CVE-2026-49458, CVE-2026-49459, and CVE-2026-49978. #GH-186
  • Security: Fixed the namespace tracker to pop all stale scopes instead of just one, closing an iframe srcdoc XSS vector reachable through namespace confusion. (CVE-2026-47760)
  • Security: Rewrote the sanitization hook to avoid a DOMPurify 3.4.9+ parentless-guard throw that could abort the sanitize walk when elements were pre-detached by the hook.

Don't miss a new hugerte release

NewReleases is sending notifications on new releases.