VulnWatch VulnWatch
← Back to dashboard
Medium github · GHSA-p5j5-4j3q-8mq8

TYPO3 HTML Sanitizer allows Cross-site Scripting

Published Jun 12, 2026 CVSS 0.0

Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.

Credits to Doyensec in collaboration with Claude and Anthropic Research for reporting this vulnerability.

Affected AI Products

anthropic claude
Get the weekly digest. Every Monday: top AI security stories of the week. Free.