rhukster/dom-sanitizer is vulnerable to Cross-Site Scripting (XSS)
56
Medium Risk
DOMSanitizer's CSS normalization decodes escape sequences before checking url() and @import values against blocked external schemes, but it skips a backslash immediately followed by a newline, which browsers remove as a line continuation. Sanitized HTML, SVG, or inline style attributes with a URL split across that line continuation keep their external scheme hidden from the filter, so the sanitizer output still fetches the untrusted external resource in a browser. The fix normalizes line endings before decoding, checks the CSS through additional normalized views, and ends a string at a raw unescaped newline the way browsers do.
You are affected if you are using a version that falls within the vulnerable range.
rhukster/dom-sanitizer is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 1.0.17.
Upgrade the rhukster/dom-sanitizer library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.