VDB
Sign up
MEDIUM

GHSA-p5j5-4j3q-8mq8

TYPO3 HTML Sanitizer allows Cross-site Scripting

Quick fix

GHSA-p5j5-4j3q-8mq8 — typo3/html-sanitizer: upgrade to the fixed version with the command below.

composer require typo3/html-sanitizer:^2.3.2

Details

Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of `typo3/html-sanitizer` before version 2.3.2.

Credits to Doyensec in collaboration with Claude and Anthropic Research for reporting this vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/typo3/html-sanitizer
Introduced in: 0Fixed in: 2.3.2
Fixcomposer require typo3/html-sanitizer:^2.3.2

References