Cross-Site Scripting Vulnerability in DOMPurify by Cure53
CVE-2026-41239
6.8MEDIUM
What is CVE-2026-41239?
A security issue exists in DOMPurify affecting versions prior to 3.4.0, where the SAFE_FOR_TEMPLATES configuration fails to adequately sanitize variables used in templating engines, specifically when using the RETURN_DOM and RETURN_DOM_FRAGMENT modes. This oversight allows malicious scripts to execute via unfiltered input in frameworks such as Vue 2, significantly compromising web application security. Version 3.4.0 addresses this vulnerability by enhancing the sanitization process.
Affected Version(s)
DOMPurify >= 1.0.10, < 3.4.0
