Skip to content

fix: avoid DOM Clobbering gadget in getRelativeUrlFromDocument#18115

Merged
patak-cat merged 1 commit intovitejs:mainfrom
jackfromeast:main
Sep 16, 2024
Merged

fix: avoid DOM Clobbering gadget in getRelativeUrlFromDocument#18115
patak-cat merged 1 commit intovitejs:mainfrom
jackfromeast:main

Conversation

@jackfromeast
Copy link
Contributor

Description

This patch fixes the DOM Clobbering gadget in the getRelativeUrlFromDocument function.

Reference: GHSA-64vr-g452-qvp3

@bolt-new-by-stackblitz
Copy link

Review PR in StackBlitz Codeflow Run & review this pull request in StackBlitz Codeflow.

@patak-cat patak-cat changed the title Patch the DOM Clobbering gadget in the getRelativeUrlFromDocument fun… fix: DOM Clobbering gadget in getRelativeUrlFromDocument Sep 16, 2024
@patak-cat
Copy link
Member

/ecosystem-ci run

@vite-ecosystem-ci
Copy link

@vite-ecosystem-ci
Copy link

Copy link
Member

@patak-cat patak-cat left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @jackfromeast!

@patak-cat patak-cat changed the title fix: DOM Clobbering gadget in getRelativeUrlFromDocument fix: avoid DOM Clobbering gadget in getRelativeUrlFromDocument Sep 16, 2024
@patak-cat patak-cat merged commit ade1d89 into vitejs:main Sep 16, 2024
patak-cat pushed a commit that referenced this pull request Sep 16, 2024
patak-cat pushed a commit that referenced this pull request Sep 17, 2024
plchampigny pushed a commit to plchampigny/vite that referenced this pull request Sep 19, 2024
moonlitusun pushed a commit to moonlitusun/vite that referenced this pull request May 25, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants