Skip to content

CommonMark has DisallowedRawHtml extension bypass via whitespace in HTML tag names

Moderate severity GitHub Reviewed Published Mar 5, 2026 in thephpleague/commonmark • Updated Mar 20, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts