MEDIUM🇬🇧 English

CVE-2026-65898

CVSS 5.1v4.0pub. 2026-07-23upd. 2026-07-28

DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to permanently mutate the shared allowlist. Attackers can register a hook that conditionally allows dangerous attributes like onerror for trusted elements, then submit untrusted content that inherits the polluted allowlist and executes event handlers as stored XSS.

oryginał EN
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Cure53 Dompurify

    APP
    Cure53
    < 3.4.11
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
XSS
CWE
Referencje

Powiązane podatności

CVE-2024-48910CRITICAL9.1PL ✓ten sam produkt

Prototype pollution w bibliotece DOMPurify umożliwiający XSS

CVE-2024-47875CRITICAL10.0PL ✓ten sam produkt

DOMPurify — podatność mXSS oparta na zagnieżdżaniu znaczników

CVE-2026-47423HIGH8.2PL ✓ten sam produkt

XSS w DOMPurify — bypass sanityzacji przez element <selectedcontent>

CVE-2024-45801HIGH7.3ten sam produkt

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discove...

CVE-2026-66010MEDIUM5.1ten sam produkt

DOMPurify przed wersją 3.4.12 nie wykonuje hook'a afterSanitizeElements dla custom elements dozwolonych przez ...