dompurify is vulnerable to Cross-Site Scripting (XSS)
37
Low Risk
DOMPurify's IN_PLACE mode force removes nodes flagged for removal and strips attributes that are not on the allow list from detached subtrees, but a raw text element such as <style> carries its payload as text content rather than attributes. If the root passed to sanitize() is such an element and gets force removed, it is detached with its markup intact and returned to the caller unsanitized. Serializing and reparsing that node in a plain HTML context runs the live markup, leading to cross-site scripting. The patch makes sanitize() throw when the root itself is force removed instead of returning it.
You are affected if you are using a version that falls within the vulnerable range and you call sanitize() with IN_PLACE: true on input whose root is a raw text element, such as <style>, that gets force removed during sanitization.
dompurify is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 3.4.15.
Upgrade the dompurify library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.