braintree / sanitize-url

MIT License
307 stars 35 forks source link

Add a Recursive Check for HTML Entities #69

Closed jplukarski closed 4 months ago

jplukarski commented 4 months ago

Recursively checks for the presence of HTML Entities.

Co authored by @ibooker

M4dHackers commented 3 months ago

As this was an XSS bypass will a CVE be issued to notify consumers of the package?

Previous CVE's for bypasses: CVE-2022-48345, CVE-2021-23648