GHSA-vhv4-fh94-jm5x
MODERATECVE-2025-29771XSS vulnerability when the sanitizer is used with a contentEditable element to set the elements innerHTML to a sanitized string produced by the package. If the code is particularly crafted to abuse the code beautifier, that runs AFTER sanitation.
- Affected
- < 2.0.3
- Fixed in
- 2.0.3
- Weakness
- CWE-79
- Published
- 2025-03-14
- Source
- github