Skip to content

Releases: cure53/DOMPurify

DOMPurify 2.3.0

06 Jul 10:28
e15ae1e
Compare
Choose a tag to compare
  • Added better handling of document creation on Firefox
  • Added better handling of version numbers in license file
  • Added two new browser versions to test suite config
  • Fixed a bug with handling of custom data attributes

DOMPurify 2.2.9

01 Jun 11:24
9de5b19
Compare
Choose a tag to compare
  • Fixed some minor issues related to the NAMESPACE config
  • Fixed some minor issues relating to empty input
  • Fixed some minor issues relating to handling of invalid XML

DOMPurify 2.2.8

28 Apr 08:06
1bf9e2a
Compare
Choose a tag to compare
  • Added NAMESPACE config option, thanks @NateScarlet
  • Added better fallback for older browsers & PhantomJS, thanks @albanx
  • Extended allow-list for SVG attributes a bit

DOMPurify 2.2.7

12 Mar 15:22
a9ad5be
Compare
Choose a tag to compare
  • Fixed handling of unsupported browsers, i.e. Safari 9 and older
  • Fixed various minor bugs and typos in README and examples
  • Added better handling of potentially harmful "is" attributes
  • Added better handling of lookupGetter functionality

DOMPurify 2.2.6

18 Dec 15:18
b11cb72
Compare
Choose a tag to compare
  • Added new mXSS prevention logic created by SecurityMB

DOMPurify 2.2.4

15 Dec 16:36
499b3bb
Compare
Choose a tag to compare
  • Fixed a new MathML-based bypass submitted by PewGrand
  • Fixed a new SVG-related bypass submitted by SecurityMB
  • Updated NodeJS CI to Node 14.x and Node 15.x
  • Cleaned up _forceRemove logic for better reliability

DOMPurify 2.2.3

07 Dec 13:25
e7086f7
Compare
Choose a tag to compare
  • Fixed an mXSS issue reported by PewGrand
  • Fixed a minor issue with the license header
  • Fixed a problem with overly-eager CSS stripping
  • Updated the README and removed an XSS warning

DOMPurify 2.2.2

02 Nov 20:04
7923e10
Compare
Choose a tag to compare
  • Fixed an mXSS bypass dropped on us publicly via #482
  • Fixed an mXSS variation that was reported privately short after
  • Added dialog to permitted elements list
  • Fixed a small typo in the README

DOMPurify 2.2.0

21 Oct 07:30
0e31dce
Compare
Choose a tag to compare
  • Fix a possible XSS in Chrome that is hidden behind #enable-experimental-web-platform-features, reported by @neilj and @mfreed7
  • Changed RETURN_DOM_IMPORT default to true to address said possible XSS
  • Updated README to reflect the new change and inform about the risks of manually setting RETURN_DOM_IMPORT back to false
  • Fixed the tests to properly address the new default

DOMPurify 2.1.1

25 Sep 11:47
32b3241
Compare
Choose a tag to compare
  • Removed some code targeting old Safari versions
  • Removed some code targeting older MS Edge versions
  • Re-added some code targeting older Chrome versions, thanks @terjanq
  • Added new tests and removed unused SAFE_FOR_JQUERY test cases
  • Added Node 14.x to existing test coverage