Skip to content

Security: dom_security_schema.ts URL list missing 12+ attribute pairs #69164

@fg0x0

Description

@fg0x0

[attr.X] binding bypasses URL sanitizer for SVG use/image/feImage, media audio/source/track, video poster, legacy background attrs, img srcset. Related: CVE-2026-22610, CVE-2026-27970, CVE-2026-32635.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: securityIssues related to built-in security features, such as HTML sanitation

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions