PT-2026-22765 · Dompurify · Dompurify

Cure53

·

Published

2026-03-03

·

Updated

2026-06-02

·

CVE-2026-0540

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions DOMPurify versions 2.5.3 through 2.5.8 DOMPurify versions 3.1.3 through 3.3.1
Description DOMPurify contains a cross-site scripting issue that allows attackers to bypass attribute sanitization. This bypass is achieved by exploiting missing rawtext elements (noscript, xmp, noembed, noframes, iframe) within the SAFE FOR XML regular expression. Attackers can inject payloads, such as , into attribute values. When the sanitized output is placed within these unprotected rawtext contexts, the JavaScript payload can be executed.
Recommendations Update to a version of DOMPurify that includes commit 729097f.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-LC05413
CVE-2026-0540
GHSA-V2WJ-7WPQ-C8VV
OPENSUSE-SU-2026:10599-1

Affected Products

Dompurify