Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-65898

Опубликовано: 23 июл. 2026
Источник: debian
EPSS Низкий

Описание

DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to permanently mutate the shared allowlist. Attackers can register a hook that conditionally allows dangerous attributes like onerror for trusted elements, then submit untrusted content that inherits the polluted allowlist and executes event handlers as stored XSS.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-dompurifyfixed3.4.12+dfsg-1package

Примечания

  • https://github.com/cure53/DOMPurify/security/advisories/GHSA-cmwh-pvxp-8882

EPSS

Процентиль: 6%
0.00167
Низкий

Связанные уязвимости

CVSS3: 7.2
ubuntu
12 дней назад

DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to permanently mutate the shared allowlist. Attackers can register a hook that conditionally allows dangerous attributes like onerror for trusted elements, then submit untrusted content that inherits the polluted allowlist and executes event handlers as stored XSS.

CVSS3: 7.2
nvd
12 дней назад

DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to permanently mutate the shared allowlist. Attackers can register a hook that conditionally allows dangerous attributes like onerror for trusted elements, then submit untrusted content that inherits the polluted allowlist and executes event handlers as stored XSS.

github
около 2 месяцев назад

DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)

EPSS

Процентиль: 6%
0.00167
Низкий