Cross-Site Scripting Vulnerability in rhukster dom-sanitizer URL Validation
CVE-2026-103686

5.1MEDIUM

Key Information:

Vendor

Rhukster

Vendor
CVE Published:
1 October 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-103686?

A security flaw exists in rhukster's dom-sanitizer component, specifically in the URL validation functionality. The issue lies within the DOMSanitizer::isDangerousUrl method, which can be exploited for cross-site scripting attacks. This vulnerability can allow attackers to initiate remote exploits, potentially compromising the security of affected applications. It is crucial for users of the dom-sanitizer to upgrade to version 1.0.16 or later, which addresses this vulnerability. The patch for this issue is identified by commit 4623b565d060bc02ca5a07d8c8241fe28e2edfda.

Affected Version(s)

dom-sanitizer 1.0.0

dom-sanitizer 1.0.1

dom-sanitizer 1.0.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

0xMo-Error (VulDB User)
.