Cross-Site Scripting Vulnerability in DOMPurify by Cure53
CVE-2026-75838
5.1MEDIUM
What is CVE-2026-75838?
DOMPurify versions before 3.4.13 are at risk of a cross-site scripting vulnerability related to IN_PLACE sanitization. This flaw arises when element-removal hooks inadequately neutralize detached subtrees. Consequently, attackers can insert malicious HTML containing event handlers on descendant elements. These handlers execute post-sanitization, compromising the intended safety of the output and potentially leading to unauthorized script execution.
Affected Version(s)
DOMPurify 0 < 3.4.13
DOMPurify 3.4.13
