PT-2026-63994 · Dompurify · Dompurify

·

CVE-2026-65914

·

Published

2026-03-27

·

Updated

2026-07-23

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions DOMPurify versions prior to 3.3.2
Description A mutation-XSS (Cross-Site Scripting) issue occurs when sanitized HTML is reinserted into special parsing contexts using innerHTML with wrappers such as script, xmp, iframe, noembed, noframes, or noscript. Attackers can use closing sequences to break out of the wrapper context during reparsing, which reactivates dangerous markup containing event handlers to execute arbitrary JavaScript.
Recommendations Update to version 3.3.2 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65914
GHSA-H8R8-WCCR-V5F2

Affected Products

Dompurify