Vulnerabilities/

JS Html Sanitizer allows XSS when used with contentEditable

Severity:
Medium

Description

XSS vulnerability when the sanitizer is used with a contentEditable element to set the elements innerHTML to a sanitized string produced by the package. If the code is particularly crafted to abuse the code beautifier, that runs AFTER sanitation.

Recommendation

Update the @jitbit/htmlsanitizer package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@jitbit/htmlsanitizer
Anything's wrong? Let us know Last updated on March 14, 2025

This issue is available in SmartScanner Professional

See Pricing