PT-2026-63985 · Dompurify · Dompurify
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
DOMPurify versions 3.0.0 through 3.4.8
Description
The software fails to reset the retained Trusted Types policy when the
clearConfig() function is called. Consequently, a DOMPurify instance reused across trust boundaries remains bound to a previously supplied TRUSTED TYPES POLICY. A subsequent caller requesting RETURN TRUSTED TYPE output receives a TrustedHTML object created by the previous, potentially unsafe policy instead of a clean default. This can result in script execution at a Trusted Types sink. Additionally, passing TRUSTED TYPES POLICY: null during a later call fails to clear the retained policy.Recommendations
Update DOMPurify to version 3.4.9 or later.
Exploit
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dompurify