CVE-2026-61825: code16/sharp has a stored XSS via data-html-content Sanitizer Bypass
The vulnerability allows an attacker to bypass the HTML sanitizer by using the data-html-content attribute in the content of a SharpEditorFormField.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-61825 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →