← Back to CVE List

CVE-2025-29771

Published: 2025-03-14T19:15Z
Last Modified: 2025-03-14T19:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
HtmlSanitizer is a client-side HTML Sanitizer. Versions prior to 2.0.3 have a cross-site scripting vulnerability when the sanitizer is used with a `contentEditable` element to set the elements `innerHTML` to a sanitized string produced by the package. If the code is particularly crafted to abuse the code beautifier, that runs AFTER sanitation. The issue is patched in version 2.0.3. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt