DOMPurify v2.0.16 Release Notes

Release Date: 2020-09-18 // over 3 years ago
    • πŸ›  Fixed an mXSS-based bypass caused by nested forms inside MathML
    • πŸ›  Fixed a security error thrown on older Chrome on Android versions, see #470

    🍱 Credits for the bypass go to MichaΕ‚ Bentkowski (@securityMB) of Securitum who spotted the bug in Chrome, turned it into another DOMPurify bypass, reported and helped verifying the fix πŸ™‡β€β™‚οΈ πŸ™‡β€β™€οΈ