DOMPurify Vulnerability in Custom Elements by Cure53
CVE-2026-66010
5.1MEDIUM
What is CVE-2026-66010?
The vulnerability in DOMPurify affects versions prior to 3.4.12, where the failure to execute the afterSanitizeElements hook for custom elements permits certain attributes to circumvent established application security policies. This oversight allows attackers to maintain sensitive attributes on custom elements, which could be later re-injected into innerHTML sinks, effectively enabling the creation of second-order cross-site scripting (XSS) gadgets. Such exploits pose a significant risk to web applications that rely heavily on DOMPurify for sanitizing input.
Affected Version(s)
DOMPurify 0 < 3.4.12
DOMPurify 3.4.12
