MEDIUM
GHSA-pgjv-jrg2-gq3v
dompurify vulnerable to Cross-site Scripting
Quick fix
GHSA-pgjv-jrg2-gq3v — dompurify: upgrade to the fixed version with the command below.
pip install --upgrade 'dompurify>=2.2.2'Details
dompurify prior to version 2.2.2 is vulnerable to cross-site scripting when converting from SVG namespace.
Are you affected?
Enter the version of the package you're using.