DOMPurify Vulnerability in Custom Elements by Cure53
CVE-2026-66010

5.1MEDIUM

Key Information:

Vendor

Cure53

Status
Vendor
CVE Published:
24 July 2026

What is CVE-2026-66010?

The vulnerability in DOMPurify affects versions prior to 3.4.12, where the failure to execute the afterSanitizeElements hook for custom elements permits certain attributes to circumvent established application security policies. This oversight allows attackers to maintain sensitive attributes on custom elements, which could be later re-injected into innerHTML sinks, effectively enabling the creation of second-order cross-site scripting (XSS) gadgets. Such exploits pose a significant risk to web applications that rely heavily on DOMPurify for sanitizing input.

Affected Version(s)

DOMPurify 0 < 3.4.12

DOMPurify 3.4.12

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rikuxx0
.