symfony/html-sanitizer is vulnerable to Cross-site Scripting (XSS)
35
Low Risk
UrlAttributeSanitizer omits several URL-valued HTML attributes from scheme validation. Permissive sanitizer configurations can therefore keep javascript: URLs in action, formaction, poster, or cite. Pre-fix sanitized content can retain scriptable URLs in allowed attributes. The fix validates those attributes against the appropriate link or media scheme policy.
You are affected if you are using a version that falls within the vulnerable range.
symfony/html-sanitizer is vulnerable to Cross-site Scripting (XSS) in versions 6.1.0 - 6.4.39, 7.0.0 - 7.4.11 and 8.0.0 - 8.0.11.
Upgrade the symfony/html-sanitizer and/or symfony/symfony library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant