Skip to content

RS-22478: Revert "fix stored XSS in metro HTML labels (#51)"#52

Merged
JustinCCYap merged 1 commit into
masterfrom
revert-RS-22478-metro-xss
Jun 16, 2026
Merged

RS-22478: Revert "fix stored XSS in metro HTML labels (#51)"#52
JustinCCYap merged 1 commit into
masterfrom
revert-RS-22478-metro-xss

Conversation

@JustinCCYap

Copy link
Copy Markdown
Contributor

Reverts commit f95425c (#51).

This removes the DOMPurify sanitisation of as_html label content (and the dompurify dependency / sanitizeConfig.js), and reverts the version bump.

Warning

The reverted commit was a stored XSS security fix (RS-22478). Merging this PR re-opens that vulnerability. Confirm this is intended before merging.

🤖 Generated with Claude Code

@JustinCCYap JustinCCYap changed the title Revert "RS-22478: fix stored XSS in metro HTML labels (#51)" RS-22478: Revert "fix stored XSS in metro HTML labels (#51)" Jun 16, 2026
@JustinCCYap JustinCCYap merged commit 771e688 into master Jun 16, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants