PT-2026-76938 · Dompurify · Dompurify

·

CVE-2026-75838

·

Published

2026-08-07

·

Updated

2026-08-19

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions DOMPurify versions prior to 3.4.13
Description An issue exists in the IN PLACE sanitization process where element-removal hooks do not properly neutralize detached subtrees. This allows attackers to provide HTML containing event handlers on descendant elements that execute after the sanitization process is finished, despite the returned root element appearing clean. This leads to cross-site scripting, a technique where malicious scripts are injected into trusted websites.
Recommendations Update to version 3.4.13 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75838
GHSA-55Q2-FJHQ-7XH7

Affected Products

Dompurify