This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
Affected surfaces
ReleasePort's take
Moderate signalThe release bumps the `sanitize-html` dependency to v2.17.5, fixing CVE-2026-53606.
Why it matters: CVE-2026-53606 is addressed by upgrading sanitize‑html to version 2.17.5; update immediately if using an earlier version.
Summary
AI summaryBump sanitize-html to v2.17.5 to fix CVE-2026-53606.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Bumps `sanitize-html` dependency to v2.17.5 fixing CVE-2026-53606. Bumps `sanitize-html` dependency to v2.17.5 fixing CVE-2026-53606. Source: llm_adapter@2026-07-16 Confidence: high |
— |
Full changelog
This release is built with Go 1.25.12 and fixes a security issue in a UI dependency.
- [SECURITY] UI: Bump
sanitize-htmlto v2.17.5 to fix CVE-2026-53606. #19060
Security Fixes
- CVE-2026-53606 — fixed by bumping `sanitize-html` dependency to v2.17.5
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Featured in
Beta — feedback welcome: [email protected]