DOMPurify 0.8.9 released
Low
Vulnerability Details
Got the following via the [DOMPurify-Security mailing list](https://lists.ruhr-uni-bochum.de/mailman/listinfo/dompurify-security):
```
*Intro*
A new version of DOMPurify was released today: DOMPurify 0.8.9
*Background*
DOMPurify showed weaknesses when handling both the recent Safari
DOMParser XSS and a Firefox mXSS when working with document.write().
Caused by a broken logical check, not all browser bugs were being worked
around correctly.
*Fix*
DOMPurify now performs better checks to mitigate both the Safari
DOMParser XSS and a Firefox mXSS when using document.write().
*Packages*
Updated packages are available here:
https://github.com/cure53/DOMPurify/releases/tag/0.8.9
EOF
```
Actions
View on HackerOneReport Stats
- Report ID: 225777
- State: Closed
- Substate: resolved
- Upvotes: 6