PT-2025-21331 · Dompurify+1 · Dompurify+1
Odaysec
·
Published
2025-05-15
·
Updated
2025-05-16
·
CVE-2025-48050
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
DOMPurify versions 3.2.5 and earlier
Description:
The issue arises from the scripts/server.js file in DOMPurify, which fails to ensure that a pathname is located under the current working directory. This problem is present in versions up to 3.2.5 before the commit 6bc6d60.
Recommendations:
For DOMPurify versions 3.2.5 and earlier, consider restricting access to the scripts/server.js file until a patch is available. As a temporary workaround, ensure that all pathnames are manually verified to be under the current working directory to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dompurify
Debian