All vulnerabilities

GHSA-CMWH-PVXP-8882

npm · dompurify

Summary

DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)

References