fix(security): bump dompurify to patch XSS vulnerability - #638
Merged
hitesh-shetty-cstk merged 2 commits intoAug 24, 2026
Conversation
DOMPurify before 3.4.13 has an XSS bypass where IN_PLACE sanitization combined with element-removal hooks can leave a detached DOM subtree with executable event handlers (GHSA-55q2-fjhq-7xh7). Bumps the dependency from ^3.4.12 to ^3.4.13, the first patched release. Co-Authored-By: Claude <noreply@anthropic.com>
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
🔒 Security Scan Results
⏱️ SLA Breach Summary
✅ BUILD PASSED - All security checks passed |
Coverage Report
File CoverageNo changed files found. |
Clears 9 advisories (8 high, 1 moderate) in postcss, vite, and ws. Lockfile only; no package.json ranges changed. Co-Authored-By: Claude <noreply@anthropic.com>
🔒 Security Scan Results
⏱️ SLA Breach Summary
✅ BUILD PASSED - All security checks passed |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
DOMPurify before 3.4.13 has an XSS bypass (GHSA-55q2-fjhq-7xh7):
IN_PLACEsanitization combined with element-removal hooks can leave a detached DOM subtree with executable event handlers, allowing script execution despite sanitization.Fix
Bumped the
dompurifydependency from^3.4.12to^3.4.13, the first patched release.Verification
Confirmed via the GitHub Advisory Database (GHSA-55q2-fjhq-7xh7) that 3.4.13 is the first patched release. Version-string bump only, no code changes; no build/test suite run.
🤖 Generated with Claude Code
Generated by Claude Code