This is a security release to address an issue where the allowed_domains setting for the Embed extension can be bypassed, resulting in a possible SSRF and XSS vulnerabilities.
Fixed
- Fixed
DomainFilteringAdapterhostname boundary bypass where domains likeyoutube.com.evilcould match an allowlist entry foryoutube.com(GHSA-hh8v-hgvp-g3f5)
Full Changelog: 2.8.1...2.8.2