PT-2025-21331 · Dompurify+1 · Dompurify+1

Odaysec

·

Published

2025-05-15

·

Updated

2025-05-16

·

CVE-2025-48050

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions: DOMPurify versions 3.2.5 and earlier
Description: The issue arises from the scripts/server.js file in DOMPurify, which fails to ensure that a pathname is located under the current working directory. This problem is present in versions up to 3.2.5 before the commit 6bc6d60.
Recommendations: For DOMPurify versions 3.2.5 and earlier, consider restricting access to the scripts/server.js file until a patch is available. As a temporary workaround, ensure that all pathnames are manually verified to be under the current working directory to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-48050

Affected Products

Dompurify
Debian