PT-2026-76938 · Dompurify · Dompurify
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
DOMPurify versions prior to 3.4.13
Description
An issue exists in the
IN PLACE sanitization process where element-removal hooks do not properly neutralize detached subtrees. This allows attackers to provide HTML containing event handlers on descendant elements that execute after the sanitization process is finished, despite the returned root element appearing clean. This leads to cross-site scripting, a technique where malicious scripts are injected into trusted websites.Recommendations
Update to version 3.4.13 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dompurify