Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.
https://pkg.go.dev/vuln/GO-2023-1988
https://go.dev/issue/61615
https://go.dev/cl/514896
Source: Mitre, NVD
Published: 2023-08-02
Updated: 2023-11-07
Base Score: 6.4
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N
Severity: Medium
Base Score: 6.1
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N