Skip to content

fix: strip on* event handlers and style attributes from allowlisted HTML tags in convertXmlTags()#22988

Merged
pelikhan merged 5 commits intomainfrom
copilot/fix-html-attribute-injection
Mar 25, 2026
Merged

fix: strip on* event handlers and style attributes from allowlisted HTML tags in convertXmlTags()#22988
pelikhan merged 5 commits intomainfrom
copilot/fix-html-attribute-injection