Skip to content

Version 2.1.4

Latest

Choose a tag to compare

@TonyMerlin TonyMerlin released this 07 Aug 11:51
5ba9e67

v2.1.4

Security

Fix: Resolved GitHub CodeQL js/xss-through-dom warning within the frontend Product Finder.

Fix: Added strict validation for attribute set profile image URLs before assigning them to frontend <img> elements.

Fix: Restricted profile images to same-origin HTTP(S) URLs within /media/merlin_productfinder/, preventing untrusted URLs from being rendered.

Changed

Change: Refactored frontend image rendering to validate image URLs before assigning the src property.

Fix: Invalid image URLs are now safely ignored, preventing unsafe DOM injection while preserving existing functionality.

Fix: Replaced malformed em-dash characters in progressive AJAX status messages with Unicode escape sequences to prevent character encoding issues.