@react-email/editor@1.5.2
Patch Changes
- 0963d30: scrub
javascript:,vbscript:, and non-imagedata:URLs from pasted HTML and dropscript,iframe,object,embed,meta, andbaseelements. This pass now runs on every paste; previously, content carrying the editor'snode-*class marker took a fast-path that skipped sanitization entirely and could be spoofed by hosting attacker HTML with the same class name. Legitimate intra-editor copy/paste still round-tripsclass,style, anddata-*attributes as before.
Fetched May 27, 2026
