Headline
GHSA-2ghm-r75j-pjx2: Cross-site Scripting in DOMSanitizer
DOMSanitizer (aka dom-sanitizer) before 1.0.7 allows XSS via an SVG document because of mishandling of comments and greedy regular expressions.
Cross-site Scripting in DOMSanitizer
Moderate severity GitHub Reviewed Published Nov 23, 2023 to the GitHub Advisory Database • Updated Nov 23, 2023
Related news
CVE-2023-49146: fix XSS attacks utilizing comments and greedy regex · rhukster/dom-sanitizer@c2a98f2
DOMSanitizer (aka dom-sanitizer) before 1.0.7 allows XSS via an SVG document because of mishandling of comments and greedy regular expressions.