Skip to content

New vulnerability with dompurify 3.4.11 #13646

Description

@philpil

What happened?

still has a vulnerability to a newer, critical Cross-Site Scripting (XSS) / configuration pollution bypass tracked under CVE-2026-49458.
patched in dompurify 3.4.12

Reproduction steps

...

Sandcastle example

No response

Environment

Browser:
CesiumJS Version:
Operating System:

AI acknowledgment

  • I used AI to generate this issue report.
  • (If the above is checked) I have reviewed the AI-generated content before submitting.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions