DOMPurify Hook Mutation Vulnerability in Cure53 Product
CVE-2026-65902

5.3MEDIUM

Key Information:

Vendor

Cure53

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2026-65902?

A vulnerability in DOMPurify prior to version 3.4.7 permits manipulation through the data.allowedTags and data.allowedAttributes arguments, allowing malicious actors to extend the permitted tag and attribute lists unexpectedly. When the sanitize method is invoked without configured allowed tags or attributes, inherited and mutated hook configurations can lead to payloads bypassing sanitization. This issue persists, as attempts to revert the configuration through removeAllHooks() or clearConfig() do not restore the initial state, necessitating the instantiation of a new DOMPurify instance to ensure secure sanitization.

Affected Version(s)

DOMPurify 0 < 3.4.7

DOMPurify 3.4.7

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

offset
.