dompurify is vulnerable to Protection Mechanism Failure
61
Medium Risk
When uponSanitizeElement or uponSanitizeAttribute hooks receive data.allowedTags or data.allowedAttributes, those fields are live references to the library's internal allow-lists. On default-config sanitize calls, those lists can alias module-level DEFAULT_ALLOWED_TAGS and DEFAULT_ALLOWED_ATTR, so a hook that widens them during one call permanently poisons defaults for the instance. Later attacker-controlled HTML sanitized without an explicit allow-list override can retain forbidden tags and attributes such as script or event handlers. The patch clones default allow-lists before hook processing when hooks are registered, matching the existing clone-before-mutate defense used for ADD_TAGS and ADD_ATTR.
You are affected if you are using a version that falls within the vulnerable range.
dompurify is vulnerable to Protection Mechanism Failure in versions 0.0.1 - 3.4.5.
Upgrade the dompurify library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant