Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Upgrade DOMPurify on Mirador 3. #4106

Open
jcoyne opened this issue Feb 14, 2025 · 0 comments
Open

Upgrade DOMPurify on Mirador 3. #4106

jcoyne opened this issue Feb 14, 2025 · 0 comments

Comments

@jcoyne
Copy link
Collaborator

jcoyne commented Feb 14, 2025

mirador@3.4.3 requires dompurify@^2.0.11

DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).

CVE-2025-26791

While I don't think this can be exploited in Mirador, it would be nice to not have the vuln scanner alerting on this issue.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant