[GHSA-cjmm-f4jc-qw8r] DOMPurify ADD_ATTR predicate skips URI validation#7428
[GHSA-cjmm-f4jc-qw8r] DOMPurify ADD_ATTR predicate skips URI validation#7428alejandl-msft wants to merge 1 commit intoalejandl-msft/advisory-improvement-7428from
Conversation
|
Hi there @cure53! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
|
Hi @alejandl-msft, where did you find information about version 2.5.9 also having a patch? https://github.com/cure53/DOMPurify/releases/tag/3.3.2 has an item called |
Updates
Comments
2.5.9 also has a patch for this