-
-
Notifications
You must be signed in to change notification settings - Fork 765
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Mutation XSS when converting from SVG namespace #482
Comments
Ooof, maybe email would have been better than a public ticket. Anyway, I deployed a fix: Do you think thus can be bypassed using your technique? |
Sorry, I did not know what the proper channel was to report this. My PoC code does not work anymore with the fix. |
Check here please https://github.com/cure53/DOMPurify#what-if-i-find-a-security-bug Either way, we will do a release now! The vector is beautiful tho, what can I say. |
Removed content for security reasons. Sorry for not following the proper disclosure guidelines in the first place.
The text was updated successfully, but these errors were encountered: