We have addressed a critical security vulnerability affecting a transitive dependency in our Forge app.
The issue originated from the library sanitize-html@2.13.0, which is vulnerable to a cross-site scripting (XSS) attack (CVE-2026-44990, CVSS 9.3) due to improper handling of raw-text elements such as xmp.
To mitigate this risk, we have updated the affected dependency to a non-vulnerable version, eliminating the exposure.