Vereyon / HtmlRuleSanitizer

A rule based HTML sanitizer built on top of the HTML Agility pack
MIT License
63 stars 19 forks source link

How to report security issues #29

Closed leeN closed 1 year ago

leeN commented 1 year ago

Hello there,

I found that is it possible to craft inputs to bypass the HtmlRule sanitizer and achieve XSS. It is not quite clear how to report them without dumping them in a public Github issue, which I'd rather avoid for obvious reasons. I tried messaging contact@vereyon.nl but got no response - so is there a better way to get in touch?

Cheers, leeN

cakkermans commented 1 year ago

Hi @leeN, sorry for missing this. I didn't check in for some time. Reach me at christ_akkermans@hotmail.com .