PT-2025-36452 · Unknown · Sanitize-Html
Published
2025-09-08
·
Updated
2025-12-23
·
CVE-2019-25225
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
sanitize-html versions prior to 2.0.0-beta
Description:
The
sanitizeHtml() function in index.js does not sanitize content when using the custom transformTags option, which is intended to convert attribute values into text. This allows malicious input to be transformed into executable code.Recommendations:
Update to sanitize-html version 2.0.0-beta or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sanitize-Html