DOMPurify XSS caused by DOM serialization and HTML reparsing
Attack Techniques & MethodsYesterday, 11:40
Both bugs appeared when an application passed a browser-created DOM tree to DOMPurify and then inserted the returned string with
innerHTML. DOMPurify inspected one tree, while the browser created a different one during the second parse. Passing the same payload as an HTML string did not work because the first parse normalized it before sanitization.• Raw-text elements — The attacker created an
xmp or iframe element through the DOM API and placed </xmp><img ... onerror=...> inside its text. DOMPurify saw the payload as text. After serialization and insertion through innerHTML, </xmp> closed the text element and the following img became active markup. This route required the application to allow the affected element through ADD_TAGS.• Attribute case mismatch — In DOMPurify
3.4.13, an XML-parsed node could preserve the uppercase attribute ONERROR. DOMPurify recognized it as dangerous after normalizing the name, but the removal step did not match the case-preserved attribute. It remained in the output, and the later HTML parse turned it into an event handler. This route required no custom sanitizer options, although the node had to come from XML, XHTML, or another case-preserving parser.The researchers reproduced both bugs in Chromium, Firefox, and WebKit. DOMPurify
3.4.14 extended the raw-text check beyond style and changed attribute removal to target the exact Attr node. The maintainers classified the changes as hardening and did not publish a security advisory.Products