dompurify is vulnerable to Improper Input Validation
42
Medium Risk
Affected versions of this package fail to properly sanitize HTML files in certain scenarios, allowing attackers to craft files where the attributes of specific elements bypass the sanitation process. This weakness can be exploited to introduce malicious data or execute attacks such as Cross-site Scripting (XSS), or other injection-based vulnerabilities.
You are affected if you are using a version that falls within the vulnerable range.
dompurify is vulnerable to Improper Input Validation in versions 1.0.0 - 2.5.7 and 3.0.0 - 3.2.2.
Upgrade the dompurify library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant