You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Security: fixed a mutation-XSS / `allowedTags` bypass affecting configurations that allow the `textarea` or `xmp` raw-text tags. `htmlparser2` 10.x did not recognize an end tag with a trailing solidus (e.g. `</textarea/>`) as closing the element, so it kept the following markup as raw text, but a spec-compliant browser treats `</textarea/>` as a valid close and parses that markup as a live element. Because raw-text content was re-emitted without escaping, a payload such as `<textarea></textarea/><img src=x onerror=...>` could smuggle non-allowlisted, executable markup through the sanitizer. The default configuration was not affected. This is now defended at two layers: `htmlparser2` was upgraded to 12.x, whose tokenizer closes these end tags correctly, and the raw text sanitize-html emits for these tags is always escaped so no `<` can reopen a tag when the output is re-parsed (`textarea`, an RCDATA element whose entities `htmlparser2` decodes, is escaped like normal text, while `xmp`, a raw-text element, has only its angle brackets escaped to avoid double-encoding already-encoded entities). Because `htmlparser2` is ESM-only from version 11 onward, `sanitize-html` now requires Node.js `>=22.12.0` (the first 22.x release in which `require()` of an ES module is available unflagged). Thanks to [bibu123456](https://github.com/bibu123456) for reporting the vulnerability and [Kayiz-PT](https://github.com/Kayiz-PT) for coordinating the disclosure (GHSA-jxwj-j7wr-gfrw).
0 commit comments