Skip to content

sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, poster, and background attributes

Moderate severity GitHub Reviewed Published Jun 11, 2026 in apostrophecms/apostrophe • Updated Jul 31, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts