Skip to content

fix: strip on* event handlers and style attributes from allowlisted HTML tags in convertXmlTags()#22988

Merged
pelikhan merged 5 commits into
mainfrom
copilot/fix-html-attribute-injection
Mar 25, 2026
Merged

fix: strip on* event handlers and style attributes from allowlisted HTML tags in convertXmlTags()#22988
pelikhan merged 5 commits into
mainfrom
copilot/fix-html-attribute-injection

Merge branch 'main' into copilot/fix-html-attribute-injection

f1def7b
Select commit
Loading
Failed to load commit list.

Select a check to view from the sidebar