GHSA-p5j5-4j3q-8mq8
MODERATECVE-2026-47345Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
- Affected
- < 2.3.2
- Fixed in
- 2.3.2
- Weakness
- CWE-79
- Published
- 2026-06-12
- Source
- github