Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: avoid DOM Clobbering gadget in getRelativeUrlFromDocument #18115

Merged
merged 1 commit into from
Sep 16, 2024

Conversation

jackfromeast
Copy link
Contributor

Description

This patch fixes the DOM Clobbering gadget in the getRelativeUrlFromDocument function.

Reference: GHSA-64vr-g452-qvp3

Copy link

stackblitz bot commented Sep 16, 2024

Review PR in StackBlitz Codeflow Run & review this pull request in StackBlitz Codeflow.

@patak-dev patak-dev changed the title Patch the DOM Clobbering gadget in the getRelativeUrlFromDocument fun… fix: DOM Clobbering gadget in getRelativeUrlFromDocument Sep 16, 2024
@patak-dev
Copy link
Member

/ecosystem-ci run

@vite-ecosystem-ci
Copy link

Copy link
Member

@patak-dev patak-dev left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @jackfromeast!

@patak-dev patak-dev changed the title fix: DOM Clobbering gadget in getRelativeUrlFromDocument fix: avoid DOM Clobbering gadget in getRelativeUrlFromDocument Sep 16, 2024
@patak-dev patak-dev merged commit ade1d89 into vitejs:main Sep 16, 2024
12 of 14 checks passed
patak-dev pushed a commit that referenced this pull request Sep 16, 2024
patak-dev pushed a commit that referenced this pull request Sep 17, 2024
plchampigny pushed a commit to plchampigny/vite that referenced this pull request Sep 19, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants