CVE-2025-29771 - CVE House
Back to Database
Status published Medium CVE-2025-29771

HtmlSanitizer vulnerable to XSS when used with contentEditable

Vulnerability Description

HtmlSanitizer is a client-side HTML Sanitizer. Versions prior to 2.0.3 have a cross-site scripting vulnerability when the sanitizer is used with a `contentEditable` element to set the elements `innerHTML` to a sanitized string produced by the package. If the code is particularly crafted to abuse the code beautifier, that runs AFTER sanitation. The issue is patched in version 2.0.3.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-29771

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

HtmlSanitizer
Vulnerable Versions:
< 2.0.3

Timeline

Official Publish: March 14th, 2025
Last Modified: March 18th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)