TYPO3 HTML Sanitizer allows Cross-site Scripting
Moderate severity
GitHub Reviewed
Published
Jun 8, 2026
in
TYPO3/html-sanitizer
•
Updated Jun 12, 2026
Description
Published by the National Vulnerability Database
Jun 8, 2026
Published to the GitHub Advisory Database
Jun 12, 2026
Reviewed
Jun 12, 2026
Last updated
Jun 12, 2026
Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of
typo3/html-sanitizerbefore version 2.3.2.Credits to Doyensec in collaboration with Claude and Anthropic Research for reporting this vulnerability.
References