bevacqua / insane

:pouting_cat: Lean and configurable whitelist-oriented HTML sanitizer
https://ponyfoo.com
MIT License
449 stars 22 forks source link

Security Issue: Request for contact #19

Open pwntester opened 3 years ago

pwntester commented 3 years ago

Hello,

The GitHub Security Lab team has found a potential vulnerability in your project. Please create a Security Advisory and invite me in to further disclose and discuss the vulnerability details and potential fix. Alternatively, please add a Security Policy containing a security email address to send the details to.

Kind regards, A

dumptyd commented 3 years ago

This is the tiniest library I could find out there for sanitizing HTML. Sucks that I'll have to go with a bigger one. Hope this gets addressed soon.

samber commented 3 years ago

@bevacqua can we push it forward 🙏 ?

insane is a very critical lib for many developers. Since this is a security issue, no one other than you can fix it...

If necessary, can you add one more maintainer to this repository?

Thanks for your help! 🤞 🔒