Skip to content

4.17.1

Latest

Choose a tag to compare

@github-actions github-actions released this 30 Sep 17:36

πŸ› Bug Fix

  • GHSA-jhhp-r3r7-v2cg Security: cleanHTML.removeEventAttributes was not enforced by the background sanitizing pass β€” sanitizeHTMLElement() only stripped onerror, so any other on* handler survived on markup that reached the editable area without safeHTML, and a drop from another window was inserted by the browser natively, unsanitized, because the drop handler was only armed after a dragstart seen in the same window. The background pass now strips every on* attribute, and drops always go through the paste plugin's sanitizing path. Reported by David Vieira Kurz (HiSolutions AG).