XSS vulnerability when the sanitizer is used with a contentEditable
element to set the elements innerHTML
to a sanitized string produced by the package. If the code is particularly crafted to abuse the code beautifier, that runs AFTER sanitation.
Patched in version 2.0.3
{ "nvd_published_at": "2025-03-14T19:15:48Z", "cwe_ids": [ "CWE-79" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2025-03-14T19:54:52Z" }