DOMPurify Vulnerability in Data Sanitization by Cure53
CVE-2025-26791

4.5MEDIUM

Key Information:

Vendor

Cure53

Status
Vendor
CVE Published:
14 February 2025

What is CVE-2025-26791?

A vulnerability in DOMPurify, prior to version 3.2.4, can result from an incorrect regular expression used within template literals. This flaw may allow attackers to execute mutation cross-site scripting (mXSS) attacks, posing a significant risk to applications that rely on this library for input sanitization. Users are advised to update to the latest version to mitigate potential security issues.

Affected Version(s)

DOMPurify 0 < 3.2.4

References

CVSS V3.1

Score:
4.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.