Security: j0k3r/graby
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
deny_attribute 'style srcdoc' is space-separated but htmLawed splits on commas: GHSA-3h6j-9x8m-rg3g's 2.5.1 fix is a no-op (srcdoc still unfiltered) and it regressed the style denial that worked in 2.5.0GHSA-rhpm-4qpj-gpx6 published
Jul 7, 2026 by j0k3rModerate -
Stored XSS via iframe srcdoc Attribute in htmLawed Sanitization ConfigGHSA-3h6j-9x8m-rg3g published
Mar 27, 2026 by j0k3rLow
Learn more about advisories related to j0k3r/graby in the GitHub Advisory Database