'sanitize-html' prior to version 1.0.3 is vulnerable to...
Moderate severity
Unreviewed
Published
Sep 8, 2025
to the GitHub Advisory Database
•
Updated Sep 8, 2025
Description
Published by the National Vulnerability Database
Sep 8, 2025
Published to the GitHub Advisory Database
Sep 8, 2025
Last updated
Sep 8, 2025
'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperreference (
href
) attribute in anchor tags (<a>
), allowing bypasses that contain different casings, whitespace characters, or hexadecimal encodings.References