© 2025-2026 PySpect
First version without a known vulnerability: 0.4.5
`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes
Fixed in: 0.4.5
lxml-html-clean has <base> tag injection through default Cleaner configuration
Fixed in: 0.4.4
lxml-html-clean has CSS @import Filter Bypass via Unicode Escapes
Fixed in: 0.4.4
HTML Cleaner allows crafted scripts in special contexts like svg or math to pass through
Fixed in: 0.4.0, c5d816f86eb3707d72a8ecf5f3823e0daa1b3808