This release fixes several security issues.
What's Changed
- Upgrade optional dompurify dependency to 3.3.1 in #3948
- Fix PDF Injection in AcroForm module allows Arbitrary JavaScript Execution vulnerability
- Fix Stored XMP Metadata Injection (Spoofing & Integrity Violation) vulnerability
- Fix Shared State Race Condition in addJS Method vulnerability
- Fix Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder vulnerability
Full Changelog: v4.0.0...v4.1.0