Cure53๐
cure53@infosec.exchange
<p>And there is fire where we walk.</p>
Posts
-
View post
RE: https://mastodon.social/@gwynnion/116859269846708028 Is this a post about LLMs?
-
View post
We built a small project to inject Trusted Types enforcing sanitizer use for all HTML sinks. Without changing any of the insecure code. https://github.com/cure53/DOMFortify Maybe it is useful for someone, especially when having to maintain an older site with too many DOMXSS sinks to fix manually.
-
View post
Version 3.4.0 of DOMPurify was released today, addressing a large number of issues reported by LLMs and real people alike. Thanks to all who contributed. https://github.com/cure53/DOMPurify/releases/tag/3.4.0 We hope everything went smoothly and that no one was overlooked in the release notes.
-
View post
In anticipation of possibly upcoming waves of OSS bugs as well maybe increasing amounts of real attacks, we have been busy hardening DOMPurify. Look at those shiny badges and improvements, LOOK OMG ๐ฑ https://github.com/cure53/dompurify?tab=readme-ov-file#dompurify Work in progress of course, but lots got done this week ๐ช๐ป
-
View post
To all the OSS projects getting swamped by AI tickets right now... IT IS TOTALLY YOUR OWN FAULT. The easy fix is to write better code. You are welcome, this advice was free. *ducks*
-
View post
DOMPurify 3.4.1 is out with lots of small improvements. Among them, a better test suite, a small fuzzer, several fixes and hardenings, and as usually we hope all went well ๐ https://github.com/cure53/DOMPurify/releases/tag/3.4.1
-
View post
We did not expect that back in 2014 ๐ฅน
-
View post
We&#39;re already seeing a spike in AI-generated PRs making the ecosystem much more secure. Words cannot describe how grateful we are for all the contributions.
-
View post
We have slightly updated the publicly available contract templates for NDA, MSA and DPA. File format is ODT as usual. Feel free to, just as before, use them as you see it fit for your own purposes ๐ https://github.com/cure53/Contracts
-
View post
DOMPurify 2.5.9 and DOMPurify 3.3.2 were released today in a rush to fix a security issue caused by jsdom&#39;s faulty tag parsing. A total of four people reported the exacty same bug within a window of three days. One did so via email, thank you. One did so via private security advisory, thank you too. One however simply published a ticket for everyone to see, the other one just dropped a CVE on us without a working fix release. Thanks for nothing. https://github.com/cure53/DOMPurify/r...
-
View post
https://blog.rice.is/post/doom-over-dns/
-
View post
๐คจ ๐ https://blog.trailofbits.com/2026/03/31/how-we-made-trail-of-bits-ai-native-so-far/
-
View post
Here&#39;s everybody&#39;s space heroes having a great time with DJT. https://edition.cnn.com/2026/04/07/science/video/donald-trump-call-artemis-ii-hnk-digvid
-
View post
We know who Angine de Poitrine really is.
-
View post
Does anyone have a contact at pwn.ai? We would kinda like to have a conversation with them...
-
View post
DOMPurify 3.3.0 is out. You can now configure which tags can have which attributes much more easily. https://github.com/cure53/DOMPurify/releases/tag/3.3.0 Thanks again to everyone who contributed to and supported the project. โค๏ธ