PT-2026-63984 · Dompurify · Dompurify

·

CVE-2026-65898

·

Published

2026-06-18

·

Updated

2026-07-23

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions DOMPurify versions prior to 3.4.11
Description An issue exists where the software fails to clone the ALLOWED ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook. This allows the hook to permanently mutate the shared allowlist. An attacker can register a hook that conditionally allows dangerous attributes, such as onerror, for trusted elements. Subsequently, untrusted content can inherit this polluted allowlist, leading to the execution of event handlers as stored Cross-Site Scripting (XSS), a technique where malicious scripts are permanently stored on the target server.
Recommendations Update to version 3.4.11 or later.

Exploit

Fix

XSS

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65898
GHSA-CMWH-PVXP-8882

Affected Products

Dompurify