MEDIUM
GHSA-p5j5-4j3q-8mq8
TYPO3 HTML Sanitizer allows Cross-site Scripting
Quick fix
GHSA-p5j5-4j3q-8mq8 — typo3/html-sanitizer: upgrade to the fixed version with the command below.
composer require typo3/html-sanitizer:^2.3.2Details
Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of `typo3/html-sanitizer` before version 2.3.2.
Credits to Doyensec in collaboration with Claude and Anthropic Research for reporting this vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/typo3/html-sanitizer
Introduced in:
0Fixed in: 2.3.2Fix
composer require typo3/html-sanitizer:^2.3.2References
- https://github.com/TYPO3/html-sanitizer/security/advisories/GHSA-p5j5-4j3q-8mq8[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-47345[ADVISORY]
- https://github.com/TYPO3/html-sanitizer/commit/8b5d0be44ded457ca993ec9ca93d859941c63764[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/html-sanitizer/CVE-2026-47345.yaml[WEB]
- https://github.com/TYPO3/html-sanitizer[PACKAGE]
- https://typo3.org/security/advisory/typo3-core-sa-2026-006[WEB]