Skip to content

Update dependency sanitize-html to ^2.18.0 - #506

Merged
mvriu5 merged 1 commit into
mainfrom
renovate/sanitize-html-2.x
Oct 9, 2026
Merged

mvriu5 merged 1 commit into
mainfrom
renovate/sanitize-html-2.x

Conversation

@renovate

@renovate renovate Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence Diffend
sanitize-html (source) ^2.17.7 → ^2.18.0 age adoption passing confidence Diff

Release Notes

apostrophecms/apostrophe (sanitize-html)

v2.18.0

Compare Source

Adds
  • Added a logger option: pass any console-shaped object, with debug, info, warn and error methods, and sanitize-html's own diagnostics are delivered to it rather than to the console, so an application with a logging pipeline of its own can route them. Missing methods, and no option at all, fall back to the console. Those messages also lost their decorative line breaks and warning icon, so each is now a single line of text; their wording is otherwise unchanged.
Fixes
  • allowedSchemesByTag is now applied to srcset and imagesrcset URLs. Previously the per-tag lookup used the attribute name instead of the tag name, so these attributes always fell back to the global allowedSchemes and ignored a tag-specific scheme allowlist. Thanks to
    spokodev for the fix.
  • Starting in version 2.17.6, sanitize-html began escaping any markup preserved inside a disallowed iframe tag, which was a change
    in behavior due to an upstream change in htmlparser2. This fix ensures such "fallback markup" is preserved without escaping, but also
    fully sanitized according to the same rules as the original input. Thanks to sumitjhacodes for
    the fix.
Security
  • When meta was allowed together with its http-equiv and content attributes, the destination URL of a <meta http-equiv="refresh" content="0;url=..."> was never checked against allowedSchemes, because it is embedded in content rather than being an attribute of its own. So javascript:, data: and other disallowed destinations passed through. The refresh URL is now extracted the way browsers do it, allowing for the different spellings, separators, quoting and letter case of url=, and checked against allowedSchemes (or allowedSchemesByTag.meta). If it is rejected, or the content cannot be parsed as a refresh, the content attribute is removed. content on other meta elements is unchanged. The default configuration does not allow meta and was not affected (CWE-79, CWE-601, GHSA-cv27-6wvh-8x7j).

    Thanks to adrbogacz for reporting the vulnerability.

  • When noscript is listed in nonTextTags, the discarded region could end too early. Browsers with scripting enabled treat <noscript> content as raw text up to the first </noscript>, but the underlying parser treats it as markup, so an end tag for an enclosing element inside <noscript> closed it implicitly and the rest of its content was emitted as ordinary sanitized markup. The discard region now continues until the point where a browser would end the <noscript> element, while implied closes of other nonTextTags such as <option> behave as before (CWE-79, CWE-436, GHSA-x3q4-9hxx-gx8m).

    Thanks to joaquiniglesiaslug for reporting the vulnerability.

  • The check that drops SVG animation elements (animate, animateColor, animateMotion, animateTransform, set) when they retarget a URL attribute such as href compared the full tag name, so a namespace-prefixed spelling like svg:animate was not recognized when such tags were allowed (for example with allowedTags: false). In XML serializations such as XHTML or standalone SVG, the prefixed element is a real animation element and could retarget a link to a javascript: URL after sanitization. The element and attributeName are now matched by their local names, ignoring any prefix (CWE-79, CWE-184, GHSA-374f-7chj-9948).

    Thanks to Kai Aizen (SnailSploit) for reporting the vulnerability.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies This updates dependency files label Oct 7, 2026
@renovate renovate Bot assigned mvriu5 Oct 7, 2026
@renovate
renovate Bot force-pushed the renovate/sanitize-html-2.x branch from 2249523 to af0e06f Compare October 9, 2026 17:03
@mvriu5
mvriu5 merged commit 382cb1f into main Oct 9, 2026
2 checks passed
@renovate
renovate Bot deleted the renovate/sanitize-html-2.x branch October 9, 2026 19:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies This updates dependency files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant