Security: cure53/DOMPurify
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
IN_PLACE hook removal leaves a detached subtree executable, causing XSSGHSA-55q2-fjhq-7xh7 published
Aug 3, 2026 by cure53Low -
`CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.GHSA-c2j3-45gr-mqc4 published
Jul 11, 2026 by cure53Low -
Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)GHSA-cmwh-pvxp-8882 published
Jun 17, 2026 by cure53Low -
Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` outputGHSA-vxr8-fq34-vvx9 published
Jun 10, 2026 by cure53Low -
SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modesGHSA-gvmj-g25r-r7wr published
May 29, 2026 by cure53Low -
`IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objectsGHSA-x4vx-rjvf-j5p4 published
May 27, 2026 by cure53Low -
DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.contentGHSA-rp9w-3fw7-7cwq published
May 27, 2026 by cure53Moderate -
Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`GHSA-76mc-f452-cxcm published
May 26, 2026 by cure53Moderate -
Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checksGHSA-hpcv-96wg-7vj8 published
May 26, 2026 by cure53Moderate -
IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOMGHSA-r47g-fvhr-h676 published
May 26, 2026 by cure53Moderate