Intel

AIKIDO-2026-211698

dompurify is vulnerable to Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS)GHSA-6688-9rhm-gjv2 Published Yesterday

37

Low Risk

This Affects:

JSdompurify
0.0.1 - 3.4.15
Fixed in 3.4.16
Are you affected? Scan for Free

TL;DR

DOMPurify's IN_PLACE mode force removes nodes flagged for removal and strips attributes that are not on the allow list from detached subtrees, but a raw text element such as <style> carries its payload as text content rather than attributes. If the root passed to sanitize() is such an element and gets force removed, it is detached with its markup intact and returned to the caller unsanitized. Serializing and reparsing that node in a plain HTML context runs the live markup, leading to cross-site scripting. The patch makes sanitize() throw when the root itself is force removed instead of returning it.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you call sanitize() with IN_PLACE: true on input whose root is a raw text element, such as <style>, that gets force removed during sanitization.

Background info

dompurify is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 3.4.15.

How to fix this

Upgrade the dompurify library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform