PT-2026-102340 · Unknown · Domsanitizer

·

CVE-2026-100370

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions DOMSanitizer versions prior to 1.0.15
Description An incomplete input-validation defect exists in the isDangerousUrl() function, which is used to reject dangerous URL values in the href and xlink:href attributes. While the javascript: scheme is rejected, the data: scheme is only rejected if the literal substring onload is present. Since data: payloads are often Base64-encoded, malicious content such as scripts or event handlers can bypass this check, allowing active markup to persist in the attributes.
Recommendations Update to version 1.0.15.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100370
GHSA-WCJ2-R6VG-RM97

Affected Products

Domsanitizer