DOMPurify allows tampering by prototype pollution Vulnerability (CVE-2024-45801)
MarcioMeier opened this issue · 3 comments
MarcioMeier commented
I have read and understood the contribution guidelines.
A high vulnerability was found in the DOMPurify library which allows XSS attack (CVE-2024-45801).
The jsPDF uses the 2.2.0 version, which should be solved by bumping to the 2.5.4 version.
HackbrettXXX commented
Thanks. Could you provide a PR?
MarcioMeier commented
Sure, I'll submit it today
MarcioMeier commented
I can confirm that the vulnerability was fixed in the version 2.5.2
Thanks @HackbrettXXX for making it quick and smooth ❤️