Skip to content

Commit

Permalink
Update history
Browse files Browse the repository at this point in the history
  • Loading branch information
rgrove committed Jul 3, 2023
1 parent 041c068 commit 773d927
Showing 1 changed file with 17 additions and 0 deletions.
17 changes: 17 additions & 0 deletions HISTORY.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,22 @@
# Sanitize History

## 6.0.2 (2023-07-06)

### Bug Fixes

* CVE-2023-36823: Fixed an HTML+CSS sanitization bypass that could allow XSS
(cross-site scripting). This issue affects Sanitize versions 3.0.0 through
6.0.1.

When using Sanitize's relaxed config or a custom config that allows `<style>`
elements and one or more CSS at-rules, carefully crafted input could be used
to sneak arbitrary HTML through Sanitize.

See the following security advisory for additional details:
[GHSA-f5ww-cq3m-q3g7](https://github.com/rgrove/sanitize/security/advisories/GHSA-f5ww-cq3m-q3g7)

Thanks to @cure53 for finding this issue.

## 6.0.1 (2023-01-27)

### Bug Fixes
Expand Down

0 comments on commit 773d927

Please sign in to comment.