VDB
Sign up

package

npm/sanitize-html

pkg:npm/sanitize-html

MEDIUM5.4npm
GHSA-vccv-cmxp-4j9h· CVE-2026-53606

sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, poster, and background attributes

Modified: 7/31/2026