sanitize
Sanitize is an allowlist-based HTML and CSS sanitizer. It removes all HTML and/or CSS from a string except the elements, attributes, and properties you choose to allow.'
Activity
- Latest release
- 1y ago
- Total releases
- 57
- Cadence
- ~2 months
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Dec 24, 2008
| Version | Released | |
|---|---|---|
7.0.0
major
| ||
6.1.3
patch
| ||
6.1.2
patch
| ||
6.1.1
patch
| ||
6.1.0
minor
| ||
6.0.2
patch
| ||
6.0.1
patch
1 CVE
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
6.0.0
major
2 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-23627
GHSA-fw3g-2h3j-qmm7
Jan 28, 2023
Improper neutralization of `noscript` element content may allow XSS in Sanitize
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize Sanitize's default configs don't allow PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using one of Sanitize's default configs or by ensuring that their custom config does not include DetailsThe root cause of this issue is that HTML parsing rules treat the contents of a ReferencesCreditThanks to David Klein from TU Braunschweig (@leeN) for reporting this issue. Affected versions
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
Fixed in
6.0.1
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
5.2.3
patch
2 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-23627
GHSA-fw3g-2h3j-qmm7
Jan 28, 2023
Improper neutralization of `noscript` element content may allow XSS in Sanitize
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize Sanitize's default configs don't allow PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using one of Sanitize's default configs or by ensuring that their custom config does not include DetailsThe root cause of this issue is that HTML parsing rules treat the contents of a ReferencesCreditThanks to David Klein from TU Braunschweig (@leeN) for reporting this issue. Affected versions
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
Fixed in
6.0.1
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
5.2.2
patch
2 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-23627
GHSA-fw3g-2h3j-qmm7
Jan 28, 2023
Improper neutralization of `noscript` element content may allow XSS in Sanitize
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize Sanitize's default configs don't allow PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using one of Sanitize's default configs or by ensuring that their custom config does not include DetailsThe root cause of this issue is that HTML parsing rules treat the contents of a ReferencesCreditThanks to David Klein from TU Braunschweig (@leeN) for reporting this issue. Affected versions
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
Fixed in
6.0.1
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
5.2.1
patch
2 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-23627
GHSA-fw3g-2h3j-qmm7
Jan 28, 2023
Improper neutralization of `noscript` element content may allow XSS in Sanitize
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize Sanitize's default configs don't allow PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using one of Sanitize's default configs or by ensuring that their custom config does not include DetailsThe root cause of this issue is that HTML parsing rules treat the contents of a ReferencesCreditThanks to David Klein from TU Braunschweig (@leeN) for reporting this issue. Affected versions
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
Fixed in
6.0.1
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
5.2.0
minor
3 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-23627
GHSA-fw3g-2h3j-qmm7
Jan 28, 2023
Improper neutralization of `noscript` element content may allow XSS in Sanitize
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize Sanitize's default configs don't allow PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using one of Sanitize's default configs or by ensuring that their custom config does not include DetailsThe root cause of this issue is that HTML parsing rules treat the contents of a ReferencesCreditThanks to David Klein from TU Braunschweig (@leeN) for reporting this issue. Affected versions
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
Fixed in
6.0.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-4054
GHSA-p4x4-rw2p-8j8m
Jun 16, 2020
Cross-site Scripting in Sanitize
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. ReleasesThis problem has been fixed in Sanitize 5.2.1. WorkaroundsIf upgrading is not possible, a workaround is to override the default value of Sanitize's
For example, if you currently use Sanitize's relaxed config, you can create a custom config object that overrides the default value of
You would then pass this custom config to Sanitize when sanitizing HTML. For more informationIf you have any questions or comments about this advisory:
CreditsMany thanks to Michal Bentkowski of Securitum for reporting this bug and helping to verify the fix. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 13 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
Fixed in
5.2.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
5.1.0
minor
3 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-23627
GHSA-fw3g-2h3j-qmm7
Jan 28, 2023
Improper neutralization of `noscript` element content may allow XSS in Sanitize
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize Sanitize's default configs don't allow PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using one of Sanitize's default configs or by ensuring that their custom config does not include DetailsThe root cause of this issue is that HTML parsing rules treat the contents of a ReferencesCreditThanks to David Klein from TU Braunschweig (@leeN) for reporting this issue. Affected versions
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
Fixed in
6.0.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-4054
GHSA-p4x4-rw2p-8j8m
Jun 16, 2020
Cross-site Scripting in Sanitize
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. ReleasesThis problem has been fixed in Sanitize 5.2.1. WorkaroundsIf upgrading is not possible, a workaround is to override the default value of Sanitize's
For example, if you currently use Sanitize's relaxed config, you can create a custom config object that overrides the default value of
You would then pass this custom config to Sanitize when sanitizing HTML. For more informationIf you have any questions or comments about this advisory:
CreditsMany thanks to Michal Bentkowski of Securitum for reporting this bug and helping to verify the fix. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 13 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
Fixed in
5.2.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
5.0.0
major
3 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-23627
GHSA-fw3g-2h3j-qmm7
Jan 28, 2023
Improper neutralization of `noscript` element content may allow XSS in Sanitize
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize Sanitize's default configs don't allow PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using one of Sanitize's default configs or by ensuring that their custom config does not include DetailsThe root cause of this issue is that HTML parsing rules treat the contents of a ReferencesCreditThanks to David Klein from TU Braunschweig (@leeN) for reporting this issue. Affected versions
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
Fixed in
6.0.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-4054
GHSA-p4x4-rw2p-8j8m
Jun 16, 2020
Cross-site Scripting in Sanitize
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. ReleasesThis problem has been fixed in Sanitize 5.2.1. WorkaroundsIf upgrading is not possible, a workaround is to override the default value of Sanitize's
For example, if you currently use Sanitize's relaxed config, you can create a custom config object that overrides the default value of
You would then pass this custom config to Sanitize when sanitizing HTML. For more informationIf you have any questions or comments about this advisory:
CreditsMany thanks to Michal Bentkowski of Securitum for reporting this bug and helping to verify the fix. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 13 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
Fixed in
5.2.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.1.1
patch
| ||
4.6.6
patch
2 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-4054
GHSA-p4x4-rw2p-8j8m
Jun 16, 2020
Cross-site Scripting in Sanitize
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. ReleasesThis problem has been fixed in Sanitize 5.2.1. WorkaroundsIf upgrading is not possible, a workaround is to override the default value of Sanitize's
For example, if you currently use Sanitize's relaxed config, you can create a custom config object that overrides the default value of
You would then pass this custom config to Sanitize when sanitizing HTML. For more informationIf you have any questions or comments about this advisory:
CreditsMany thanks to Michal Bentkowski of Securitum for reporting this bug and helping to verify the fix. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 13 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
Fixed in
5.2.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
4.6.5
patch
2 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-4054
GHSA-p4x4-rw2p-8j8m
Jun 16, 2020
Cross-site Scripting in Sanitize
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. ReleasesThis problem has been fixed in Sanitize 5.2.1. WorkaroundsIf upgrading is not possible, a workaround is to override the default value of Sanitize's
For example, if you currently use Sanitize's relaxed config, you can create a custom config object that overrides the default value of
You would then pass this custom config to Sanitize when sanitizing HTML. For more informationIf you have any questions or comments about this advisory:
CreditsMany thanks to Michal Bentkowski of Securitum for reporting this bug and helping to verify the fix. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 13 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
Fixed in
5.2.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
4.6.4
patch
2 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-4054
GHSA-p4x4-rw2p-8j8m
Jun 16, 2020
Cross-site Scripting in Sanitize
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. ReleasesThis problem has been fixed in Sanitize 5.2.1. WorkaroundsIf upgrading is not possible, a workaround is to override the default value of Sanitize's
For example, if you currently use Sanitize's relaxed config, you can create a custom config object that overrides the default value of
You would then pass this custom config to Sanitize when sanitizing HTML. For more informationIf you have any questions or comments about this advisory:
CreditsMany thanks to Michal Bentkowski of Securitum for reporting this bug and helping to verify the fix. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 13 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
Fixed in
5.2.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
4.6.3
patch
2 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-4054
GHSA-p4x4-rw2p-8j8m
Jun 16, 2020
Cross-site Scripting in Sanitize
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. ReleasesThis problem has been fixed in Sanitize 5.2.1. WorkaroundsIf upgrading is not possible, a workaround is to override the default value of Sanitize's
For example, if you currently use Sanitize's relaxed config, you can create a custom config object that overrides the default value of
You would then pass this custom config to Sanitize when sanitizing HTML. For more informationIf you have any questions or comments about this advisory:
CreditsMany thanks to Michal Bentkowski of Securitum for reporting this bug and helping to verify the fix. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 13 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
Fixed in
5.2.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
4.6.2
patch
3 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-4054
GHSA-p4x4-rw2p-8j8m
Jun 16, 2020
Cross-site Scripting in Sanitize
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. ReleasesThis problem has been fixed in Sanitize 5.2.1. WorkaroundsIf upgrading is not possible, a workaround is to override the default value of Sanitize's
For example, if you currently use Sanitize's relaxed config, you can create a custom config object that overrides the default value of
You would then pass this custom config to Sanitize when sanitizing HTML. For more informationIf you have any questions or comments about this advisory:
CreditsMany thanks to Michal Bentkowski of Securitum for reporting this bug and helping to verify the fix. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 13 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
Fixed in
5.2.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2018-3740
GHSA-7f42-p84j-f58p
Mar 21, 2018
Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
When Sanitize <= 4.6.2 is used in combination with libxml2 >= 2.9.2, a specially crafted HTML fragment can cause libxml2 to generate improperly escaped output, allowing non-whitelisted attributes to be used on whitelisted elements. This can allow HTML and JavaScript injection, which could result in XSS if Sanitize's output is served to browsers. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 6 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
Fixed in
4.6.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.6.1
patch
3 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-4054
GHSA-p4x4-rw2p-8j8m
Jun 16, 2020
Cross-site Scripting in Sanitize
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. ReleasesThis problem has been fixed in Sanitize 5.2.1. WorkaroundsIf upgrading is not possible, a workaround is to override the default value of Sanitize's
For example, if you currently use Sanitize's relaxed config, you can create a custom config object that overrides the default value of
You would then pass this custom config to Sanitize when sanitizing HTML. For more informationIf you have any questions or comments about this advisory:
CreditsMany thanks to Michal Bentkowski of Securitum for reporting this bug and helping to verify the fix. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 13 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
Fixed in
5.2.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2018-3740
GHSA-7f42-p84j-f58p
Mar 21, 2018
Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
When Sanitize <= 4.6.2 is used in combination with libxml2 >= 2.9.2, a specially crafted HTML fragment can cause libxml2 to generate improperly escaped output, allowing non-whitelisted attributes to be used on whitelisted elements. This can allow HTML and JavaScript injection, which could result in XSS if Sanitize's output is served to browsers. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 6 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
Fixed in
4.6.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.6.0
minor
3 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-4054
GHSA-p4x4-rw2p-8j8m
Jun 16, 2020
Cross-site Scripting in Sanitize
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. ReleasesThis problem has been fixed in Sanitize 5.2.1. WorkaroundsIf upgrading is not possible, a workaround is to override the default value of Sanitize's
For example, if you currently use Sanitize's relaxed config, you can create a custom config object that overrides the default value of
You would then pass this custom config to Sanitize when sanitizing HTML. For more informationIf you have any questions or comments about this advisory:
CreditsMany thanks to Michal Bentkowski of Securitum for reporting this bug and helping to verify the fix. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 13 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
Fixed in
5.2.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2018-3740
GHSA-7f42-p84j-f58p
Mar 21, 2018
Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
When Sanitize <= 4.6.2 is used in combination with libxml2 >= 2.9.2, a specially crafted HTML fragment can cause libxml2 to generate improperly escaped output, allowing non-whitelisted attributes to be used on whitelisted elements. This can allow HTML and JavaScript injection, which could result in XSS if Sanitize's output is served to browsers. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 6 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
Fixed in
4.6.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.5.0
minor
3 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-4054
GHSA-p4x4-rw2p-8j8m
Jun 16, 2020
Cross-site Scripting in Sanitize
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. ReleasesThis problem has been fixed in Sanitize 5.2.1. WorkaroundsIf upgrading is not possible, a workaround is to override the default value of Sanitize's
For example, if you currently use Sanitize's relaxed config, you can create a custom config object that overrides the default value of
You would then pass this custom config to Sanitize when sanitizing HTML. For more informationIf you have any questions or comments about this advisory:
CreditsMany thanks to Michal Bentkowski of Securitum for reporting this bug and helping to verify the fix. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 13 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
Fixed in
5.2.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2018-3740
GHSA-7f42-p84j-f58p
Mar 21, 2018
Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
When Sanitize <= 4.6.2 is used in combination with libxml2 >= 2.9.2, a specially crafted HTML fragment can cause libxml2 to generate improperly escaped output, allowing non-whitelisted attributes to be used on whitelisted elements. This can allow HTML and JavaScript injection, which could result in XSS if Sanitize's output is served to browsers. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 6 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
Fixed in
4.6.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.4.0
minor
3 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-4054
GHSA-p4x4-rw2p-8j8m
Jun 16, 2020
Cross-site Scripting in Sanitize
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. ReleasesThis problem has been fixed in Sanitize 5.2.1. WorkaroundsIf upgrading is not possible, a workaround is to override the default value of Sanitize's
For example, if you currently use Sanitize's relaxed config, you can create a custom config object that overrides the default value of
You would then pass this custom config to Sanitize when sanitizing HTML. For more informationIf you have any questions or comments about this advisory:
CreditsMany thanks to Michal Bentkowski of Securitum for reporting this bug and helping to verify the fix. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 13 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
Fixed in
5.2.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2018-3740
GHSA-7f42-p84j-f58p
Mar 21, 2018
Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
When Sanitize <= 4.6.2 is used in combination with libxml2 >= 2.9.2, a specially crafted HTML fragment can cause libxml2 to generate improperly escaped output, allowing non-whitelisted attributes to be used on whitelisted elements. This can allow HTML and JavaScript injection, which could result in XSS if Sanitize's output is served to browsers. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 6 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
Fixed in
4.6.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.3.0
minor
3 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-4054
GHSA-p4x4-rw2p-8j8m
Jun 16, 2020
Cross-site Scripting in Sanitize
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. ReleasesThis problem has been fixed in Sanitize 5.2.1. WorkaroundsIf upgrading is not possible, a workaround is to override the default value of Sanitize's
For example, if you currently use Sanitize's relaxed config, you can create a custom config object that overrides the default value of
You would then pass this custom config to Sanitize when sanitizing HTML. For more informationIf you have any questions or comments about this advisory:
CreditsMany thanks to Michal Bentkowski of Securitum for reporting this bug and helping to verify the fix. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 13 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
Fixed in
5.2.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2018-3740
GHSA-7f42-p84j-f58p
Mar 21, 2018
Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
When Sanitize <= 4.6.2 is used in combination with libxml2 >= 2.9.2, a specially crafted HTML fragment can cause libxml2 to generate improperly escaped output, allowing non-whitelisted attributes to be used on whitelisted elements. This can allow HTML and JavaScript injection, which could result in XSS if Sanitize's output is served to browsers. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 6 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
Fixed in
4.6.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.2.0
minor
3 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-4054
GHSA-p4x4-rw2p-8j8m
Jun 16, 2020
Cross-site Scripting in Sanitize
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. ReleasesThis problem has been fixed in Sanitize 5.2.1. WorkaroundsIf upgrading is not possible, a workaround is to override the default value of Sanitize's
For example, if you currently use Sanitize's relaxed config, you can create a custom config object that overrides the default value of
You would then pass this custom config to Sanitize when sanitizing HTML. For more informationIf you have any questions or comments about this advisory:
CreditsMany thanks to Michal Bentkowski of Securitum for reporting this bug and helping to verify the fix. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 13 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
Fixed in
5.2.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2018-3740
GHSA-7f42-p84j-f58p
Mar 21, 2018
Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
When Sanitize <= 4.6.2 is used in combination with libxml2 >= 2.9.2, a specially crafted HTML fragment can cause libxml2 to generate improperly escaped output, allowing non-whitelisted attributes to be used on whitelisted elements. This can allow HTML and JavaScript injection, which could result in XSS if Sanitize's output is served to browsers. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 6 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
Fixed in
4.6.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.1.0
minor
3 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-4054
GHSA-p4x4-rw2p-8j8m
Jun 16, 2020
Cross-site Scripting in Sanitize
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. ReleasesThis problem has been fixed in Sanitize 5.2.1. WorkaroundsIf upgrading is not possible, a workaround is to override the default value of Sanitize's
For example, if you currently use Sanitize's relaxed config, you can create a custom config object that overrides the default value of
You would then pass this custom config to Sanitize when sanitizing HTML. For more informationIf you have any questions or comments about this advisory:
CreditsMany thanks to Michal Bentkowski of Securitum for reporting this bug and helping to verify the fix. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 13 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
Fixed in
5.2.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2018-3740
GHSA-7f42-p84j-f58p
Mar 21, 2018
Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
When Sanitize <= 4.6.2 is used in combination with libxml2 >= 2.9.2, a specially crafted HTML fragment can cause libxml2 to generate improperly escaped output, allowing non-whitelisted attributes to be used on whitelisted elements. This can allow HTML and JavaScript injection, which could result in XSS if Sanitize's output is served to browsers. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 6 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
Fixed in
4.6.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.0.1
patch
3 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-4054
GHSA-p4x4-rw2p-8j8m
Jun 16, 2020
Cross-site Scripting in Sanitize
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. ReleasesThis problem has been fixed in Sanitize 5.2.1. WorkaroundsIf upgrading is not possible, a workaround is to override the default value of Sanitize's
For example, if you currently use Sanitize's relaxed config, you can create a custom config object that overrides the default value of
You would then pass this custom config to Sanitize when sanitizing HTML. For more informationIf you have any questions or comments about this advisory:
CreditsMany thanks to Michal Bentkowski of Securitum for reporting this bug and helping to verify the fix. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 13 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
Fixed in
5.2.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2018-3740
GHSA-7f42-p84j-f58p
Mar 21, 2018
Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
When Sanitize <= 4.6.2 is used in combination with libxml2 >= 2.9.2, a specially crafted HTML fragment can cause libxml2 to generate improperly escaped output, allowing non-whitelisted attributes to be used on whitelisted elements. This can allow HTML and JavaScript injection, which could result in XSS if Sanitize's output is served to browsers. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 6 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
Fixed in
4.6.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.0.0
major
3 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-4054
GHSA-p4x4-rw2p-8j8m
Jun 16, 2020
Cross-site Scripting in Sanitize
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. ReleasesThis problem has been fixed in Sanitize 5.2.1. WorkaroundsIf upgrading is not possible, a workaround is to override the default value of Sanitize's
For example, if you currently use Sanitize's relaxed config, you can create a custom config object that overrides the default value of
You would then pass this custom config to Sanitize when sanitizing HTML. For more informationIf you have any questions or comments about this advisory:
CreditsMany thanks to Michal Bentkowski of Securitum for reporting this bug and helping to verify the fix. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 13 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
Fixed in
5.2.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2018-3740
GHSA-7f42-p84j-f58p
Mar 21, 2018
Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
When Sanitize <= 4.6.2 is used in combination with libxml2 >= 2.9.2, a specially crafted HTML fragment can cause libxml2 to generate improperly escaped output, allowing non-whitelisted attributes to be used on whitelisted elements. This can allow HTML and JavaScript injection, which could result in XSS if Sanitize's output is served to browsers. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 6 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
Fixed in
4.6.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
3.1.2
patch
3 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-4054
GHSA-p4x4-rw2p-8j8m
Jun 16, 2020
Cross-site Scripting in Sanitize
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. ReleasesThis problem has been fixed in Sanitize 5.2.1. WorkaroundsIf upgrading is not possible, a workaround is to override the default value of Sanitize's
For example, if you currently use Sanitize's relaxed config, you can create a custom config object that overrides the default value of
You would then pass this custom config to Sanitize when sanitizing HTML. For more informationIf you have any questions or comments about this advisory:
CreditsMany thanks to Michal Bentkowski of Securitum for reporting this bug and helping to verify the fix. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 13 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
Fixed in
5.2.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2018-3740
GHSA-7f42-p84j-f58p
Mar 21, 2018
Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
When Sanitize <= 4.6.2 is used in combination with libxml2 >= 2.9.2, a specially crafted HTML fragment can cause libxml2 to generate improperly escaped output, allowing non-whitelisted attributes to be used on whitelisted elements. This can allow HTML and JavaScript injection, which could result in XSS if Sanitize's output is served to browsers. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 6 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
Fixed in
4.6.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
3.1.1
patch
3 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-4054
GHSA-p4x4-rw2p-8j8m
Jun 16, 2020
Cross-site Scripting in Sanitize
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. ReleasesThis problem has been fixed in Sanitize 5.2.1. WorkaroundsIf upgrading is not possible, a workaround is to override the default value of Sanitize's
For example, if you currently use Sanitize's relaxed config, you can create a custom config object that overrides the default value of
You would then pass this custom config to Sanitize when sanitizing HTML. For more informationIf you have any questions or comments about this advisory:
CreditsMany thanks to Michal Bentkowski of Securitum for reporting this bug and helping to verify the fix. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 13 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
Fixed in
5.2.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2018-3740
GHSA-7f42-p84j-f58p
Mar 21, 2018
Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
When Sanitize <= 4.6.2 is used in combination with libxml2 >= 2.9.2, a specially crafted HTML fragment can cause libxml2 to generate improperly escaped output, allowing non-whitelisted attributes to be used on whitelisted elements. This can allow HTML and JavaScript injection, which could result in XSS if Sanitize's output is served to browsers. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 6 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
Fixed in
4.6.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
3.1.0
minor
3 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-4054
GHSA-p4x4-rw2p-8j8m
Jun 16, 2020
Cross-site Scripting in Sanitize
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. ReleasesThis problem has been fixed in Sanitize 5.2.1. WorkaroundsIf upgrading is not possible, a workaround is to override the default value of Sanitize's
For example, if you currently use Sanitize's relaxed config, you can create a custom config object that overrides the default value of
You would then pass this custom config to Sanitize when sanitizing HTML. For more informationIf you have any questions or comments about this advisory:
CreditsMany thanks to Michal Bentkowski of Securitum for reporting this bug and helping to verify the fix. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 13 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
Fixed in
5.2.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2018-3740
GHSA-7f42-p84j-f58p
Mar 21, 2018
Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
When Sanitize <= 4.6.2 is used in combination with libxml2 >= 2.9.2, a specially crafted HTML fragment can cause libxml2 to generate improperly escaped output, allowing non-whitelisted attributes to be used on whitelisted elements. This can allow HTML and JavaScript injection, which could result in XSS if Sanitize's output is served to browsers. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 6 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
Fixed in
4.6.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
3.0.4
patch
3 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-4054
GHSA-p4x4-rw2p-8j8m
Jun 16, 2020
Cross-site Scripting in Sanitize
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. ReleasesThis problem has been fixed in Sanitize 5.2.1. WorkaroundsIf upgrading is not possible, a workaround is to override the default value of Sanitize's
For example, if you currently use Sanitize's relaxed config, you can create a custom config object that overrides the default value of
You would then pass this custom config to Sanitize when sanitizing HTML. For more informationIf you have any questions or comments about this advisory:
CreditsMany thanks to Michal Bentkowski of Securitum for reporting this bug and helping to verify the fix. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 13 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
Fixed in
5.2.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2018-3740
GHSA-7f42-p84j-f58p
Mar 21, 2018
Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
When Sanitize <= 4.6.2 is used in combination with libxml2 >= 2.9.2, a specially crafted HTML fragment can cause libxml2 to generate improperly escaped output, allowing non-whitelisted attributes to be used on whitelisted elements. This can allow HTML and JavaScript injection, which could result in XSS if Sanitize's output is served to browsers. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 6 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
Fixed in
4.6.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
3.0.3
patch
3 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-4054
GHSA-p4x4-rw2p-8j8m
Jun 16, 2020
Cross-site Scripting in Sanitize
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. ReleasesThis problem has been fixed in Sanitize 5.2.1. WorkaroundsIf upgrading is not possible, a workaround is to override the default value of Sanitize's
For example, if you currently use Sanitize's relaxed config, you can create a custom config object that overrides the default value of
You would then pass this custom config to Sanitize when sanitizing HTML. For more informationIf you have any questions or comments about this advisory:
CreditsMany thanks to Michal Bentkowski of Securitum for reporting this bug and helping to verify the fix. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 13 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
Fixed in
5.2.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2018-3740
GHSA-7f42-p84j-f58p
Mar 21, 2018
Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
When Sanitize <= 4.6.2 is used in combination with libxml2 >= 2.9.2, a specially crafted HTML fragment can cause libxml2 to generate improperly escaped output, allowing non-whitelisted attributes to be used on whitelisted elements. This can allow HTML and JavaScript injection, which could result in XSS if Sanitize's output is served to browsers. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 6 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
Fixed in
4.6.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
3.0.2
patch
3 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-4054
GHSA-p4x4-rw2p-8j8m
Jun 16, 2020
Cross-site Scripting in Sanitize
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. ReleasesThis problem has been fixed in Sanitize 5.2.1. WorkaroundsIf upgrading is not possible, a workaround is to override the default value of Sanitize's
For example, if you currently use Sanitize's relaxed config, you can create a custom config object that overrides the default value of
You would then pass this custom config to Sanitize when sanitizing HTML. For more informationIf you have any questions or comments about this advisory:
CreditsMany thanks to Michal Bentkowski of Securitum for reporting this bug and helping to verify the fix. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 13 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
Fixed in
5.2.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2018-3740
GHSA-7f42-p84j-f58p
Mar 21, 2018
Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
When Sanitize <= 4.6.2 is used in combination with libxml2 >= 2.9.2, a specially crafted HTML fragment can cause libxml2 to generate improperly escaped output, allowing non-whitelisted attributes to be used on whitelisted elements. This can allow HTML and JavaScript injection, which could result in XSS if Sanitize's output is served to browsers. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 6 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
Fixed in
4.6.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
3.0.1
patch
3 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-4054
GHSA-p4x4-rw2p-8j8m
Jun 16, 2020
Cross-site Scripting in Sanitize
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. ReleasesThis problem has been fixed in Sanitize 5.2.1. WorkaroundsIf upgrading is not possible, a workaround is to override the default value of Sanitize's
For example, if you currently use Sanitize's relaxed config, you can create a custom config object that overrides the default value of
You would then pass this custom config to Sanitize when sanitizing HTML. For more informationIf you have any questions or comments about this advisory:
CreditsMany thanks to Michal Bentkowski of Securitum for reporting this bug and helping to verify the fix. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 13 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
Fixed in
5.2.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2018-3740
GHSA-7f42-p84j-f58p
Mar 21, 2018
Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
When Sanitize <= 4.6.2 is used in combination with libxml2 >= 2.9.2, a specially crafted HTML fragment can cause libxml2 to generate improperly escaped output, allowing non-whitelisted attributes to be used on whitelisted elements. This can allow HTML and JavaScript injection, which could result in XSS if Sanitize's output is served to browsers. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 6 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
Fixed in
4.6.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
3.0.0
major
3 CVEs
CVE-2023-36823
GHSA-f5ww-cq3m-q3g7
Jul 06, 2023
Sanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element content
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize PatchesSanitize WorkaroundsUsers who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow CreditThis issue was found by @cure53 during an audit of a project that uses Sanitize and was reported by one of that project's maintainers. Thank you! Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 18 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
5.2.1
5.2.2
5.2.3
6.0.0
6.0.1
Fixed in
6.0.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-4054
GHSA-p4x4-rw2p-8j8m
Jun 16, 2020
Cross-site Scripting in Sanitize
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
When HTML is sanitized using Sanitize's "relaxed" config or a custom config that allows certain elements, some content in a You are likely to be vulnerable to this issue if you use Sanitize's relaxed config or a custom config that allows one or more of the following HTML elements:
ImpactUsing carefully crafted input, an attacker may be able to sneak arbitrary HTML through Sanitize, potentially resulting in XSS (cross-site scripting) or other undesired behavior when that HTML is rendered in a browser. ReleasesThis problem has been fixed in Sanitize 5.2.1. WorkaroundsIf upgrading is not possible, a workaround is to override the default value of Sanitize's
For example, if you currently use Sanitize's relaxed config, you can create a custom config object that overrides the default value of
You would then pass this custom config to Sanitize when sanitizing HTML. For more informationIf you have any questions or comments about this advisory:
CreditsMany thanks to Michal Bentkowski of Securitum for reporting this bug and helping to verify the fix. References
Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 13 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.6.4
4.6.5
4.6.6
5.0.0
5.1.0
5.2.0
Fixed in
5.2.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2018-3740
GHSA-7f42-p84j-f58p
Mar 21, 2018
Sanitize vulnerable to Improper Input Validation and Cross-site Scripting
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
When Sanitize <= 4.6.2 is used in combination with libxml2 >= 2.9.2, a specially crafted HTML fragment can cause libxml2 to generate improperly escaped output, allowing non-whitelisted attributes to be used on whitelisted elements. This can allow HTML and JavaScript injection, which could result in XSS if Sanitize's output is served to browsers. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
4.0.0
4.0.1
4.1.0
4.2.0
+ 6 more Show less
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
Fixed in
4.6.3
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
2.1.0
minor
| ||
2.0.6
patch
| ||
2.0.5
patch
| ||
2.0.4
patch
| ||
2.0.3
patch
| ||
2.0.2
patch
| ||
2.0.1
patch
| ||
2.0.0
major
| ||
1.2.1
patch
| ||
1.2.0
minor
| ||
1.1.0
minor
| ||
1.0.8
patch
| ||
1.0.7
patch
|