Intel

AIKIDO-2026-289156

dompurify is vulnerable to Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS)GHSA-p98j-92pf-mc4p Published Yesterday

31

Low Risk

This Affects:

JSdompurify
3.4.13 - 3.4.15
Fixed in 3.4.16
Are you affected? Scan for Free

TL;DR

DOMPurify's IN_PLACE mode sanitizes the caller's live DOM subtree. When a hook removes a node during sanitization, the removed subtree must still have its attributes stripped before sanitize() returns, but that step only ran for the beforeSanitizeElements and uponSanitizeElement hooks. A hook registered at afterSanitizeElements, beforeSanitizeAttributes, or afterSanitizeAttributes that removes a non-root element leaves its detached subtree with attributes that are not on the allow list, so descendant on* handlers stay in the caller's live tree after sanitize() returns, leading to DOM based cross-site scripting. The patch runs the same check at every per node hook site that can detach a node.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you call sanitize() with IN_PLACE: true together with a hook that removes a node other than the sanitization root.

Background info

dompurify is vulnerable to Cross-Site Scripting (XSS) in versions 3.4.13 - 3.4.15.

How to fix this

Upgrade the dompurify library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform