Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-2ghm-r75j-pjx2: Cross-site Scripting in DOMSanitizer

DOMSanitizer (aka dom-sanitizer) before 1.0.7 allows XSS via an SVG document because of mishandling of comments and greedy regular expressions.

ghsa
#xss#git

Cross-site Scripting in DOMSanitizer

Moderate severity GitHub Reviewed Published Nov 23, 2023 to the GitHub Advisory Database • Updated Nov 23, 2023

Related news

CVE-2023-49146: fix XSS attacks utilizing comments and greedy regex · rhukster/dom-sanitizer@c2a98f2

DOMSanitizer (aka dom-sanitizer) before 1.0.7 allows XSS via an SVG document because of mishandling of comments and greedy regular expressions.