Security: cure53/DOMPurify
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
DOMPurify XSS via `selectedcontent` re-cloneGHSA-87xg-pxx2-7hvx published
May 19, 2026 by cure53High -
Prototype Pollution to XSS Bypass via CUSTOM_ELEMENT_HANDLING FallbackGHSA-v9jr-rg53-9pgp published
Apr 20, 2026 by cure53Moderate -
ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluationGHSA-39q2-94rc-95cp published
Apr 15, 2026 by cure53Moderate -
Dompurify SAFE_FOR_TEMPLATES bypass in RETURN_DOM modeGHSA-crv5-9vww-q3g8 published
Apr 20, 2026 by cure53Moderate -
FORBID_TAGS bypassed by function-based ADD_TAGS predicate (asymmetry with FORBID_ATTR fix)GHSA-h7mw-gpvr-xq4m published
Apr 20, 2026 by cure53Moderate -
DOMPurify IN_PLACE mode fails to sanitize cross-window DOM elements, allowing XSS bypassGHSA-4w3q-35jp-p934 published
Apr 1, 2026 by cure53Low -
XSS via ADD_ATTR/ADD_TAGS Function Predicate State Leakage Across sanitize() CallsGHSA-9p3w-6h5p-cv75 published
Apr 1, 2026 by cure53Low -
DOMPurify ADD_ATTR predicate skips URI validationGHSA-cjmm-f4jc-qw8r published
Apr 1, 2026 by cure53Moderate -
DOMPurify USE_PROFILES prototype pollution allows event handlersGHSA-cj63-jhhr-wcxv published
Apr 1, 2026 by cure53Moderate -
DOMPurify mXSS via Re-ContextualizationGHSA-h8r8-wccr-v5f2 published
Mar 25, 2026 by cure53Moderate