Description
tag.ex in Phoenix Phoenix.HTML (aka phoenix_html) before 3.0.4 allows XSS in HEEx class attributes
Recommendation
Update the phoenix_html package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.0.4
- Patched version(s): 3.0.4
References
Related Issues
- Solid Lacks Escaping of HTML in JSX Fragments allows for Cross-Site Scripting (XSS) - CVE-2025-27109
- Cross-site Scripting in quill - CVE-2021-3163
- Docsify vulnerable to cross-site scripting due to mishandled encoding - CVE-2021-30074
- Cross-site Scripting in Froala Editor - froala-editor - CVE-2021-30109
You might also like:
- Tags:
- npm
- phoenix_html
Anything's wrong? Let us know Last updated on April 06, 2023


