Mutation-XSS Vulnerability in DOMPurify by Cure53
CVE-2026-65914

5.3MEDIUM

Key Information:

Vendor

Cure53

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2026-65914?

DOMPurify versions before 3.3.2 are susceptible to a mutation-XSS vulnerability that arises when sanitized HTML is reinserted into specific parsing contexts. This occurs through the use of innerHTML with wrappers like script, xmp, iframe, noembed, noframes, or noscript. Malicious attackers can exploit this flaw by crafting payloads that utilize closing sequences to escape the wrapper context during reparsing. Once this occurs, harmful markup can be reactivated, allowing the execution of arbitrary JavaScript due to the event handlers embedded within the markup.

Affected Version(s)

DOMPurify 0 < 3.3.2

DOMPurify 3.3.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

researchatfluidattacks
caverav
tachote
.