diff --git a/HISTORY.md b/HISTORY.md index 4d14d0c..287aa0b 100644 --- a/HISTORY.md +++ b/HISTORY.md @@ -1,5 +1,22 @@ # Sanitize History +## 6.0.2 (2023-07-06) + +### Bug Fixes + +* CVE-2023-36823: Fixed an HTML+CSS sanitization bypass that could allow XSS + (cross-site scripting). This issue affects Sanitize versions 3.0.0 through + 6.0.1. + + When using Sanitize's relaxed config or a custom config that allows `], + @s.fragment(%[]) + ) + end + end end