Skip to content

2.0.17

Latest

Choose a tag to compare

@rhukster rhukster released this 07 Aug 16:14
d7bfcb5

Bugfix

  • [security] Updated the bundled DOM sanitizer to 1.0.13, which stops CSS comments from hiding dangerous values and covers image loading through image-set(), so untrusted SVG or HTML can no longer reference external resources those ways (GHSA-ww22-4mqv-x5w3).