MEDIUM
GHSA-h6p3-p4vx-wr8q
dompurify vulnerable to Cross-site Scripting
Quick fix
GHSA-h6p3-p4vx-wr8q — dompurify: upgrade to the fixed version with the command below.
pip install --upgrade 'dompurify>=2.2.3'Details
dompurify prior to version 2.2.3 is vulnerable to a cross-site scripting problem caused by nested headlines.
Are you affected?
Enter the version of the package you're using.