What happened?
still has a vulnerability to a newer, critical Cross-Site Scripting (XSS) / configuration pollution bypass tracked under CVE-2026-49458.
patched in dompurify 3.4.12
Reproduction steps
...
Sandcastle example
No response
Environment
Browser:
CesiumJS Version:
Operating System:
AI acknowledgment
What happened?
still has a vulnerability to a newer, critical Cross-Site Scripting (XSS) / configuration pollution bypass tracked under CVE-2026-49458.
patched in dompurify 3.4.12
Reproduction steps
...
Sandcastle example
No response
Environment
Browser:
CesiumJS Version:
Operating System:
AI acknowledgment