Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-10861

Опубликовано: 04 апр. 2026
Источник: fstec
CVSS3: 6.9
CVSS2: 6.1
EPSS Низкий

Описание

Уязвимость функции DOMPurify.sanitize() JavaScript-библиотеки для безопасной очистки и защиты HTML-кода DOMPurify связана с непринятием мер по защите структуры веб-страницы. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, выполнить произвольный код

Вендор

АО «СберТех»
Cure53

Наименование ПО

Platform V IAM SE
DOMPurify

Версия ПО

до 2.3.1 (Platform V IAM SE)
от 3.0.1 до 3.3.3 включительно (DOMPurify)

Тип ПО

Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

-

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 6,1)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 6,9)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://github.com/cure53/DOMPurify/releases/tag/3.4.0
https://github.com/cure53/DOMPurify/security/advisories/GHSA-v9jr-rg53-9pgp
Для Platform V IAM SE:
Обновление до версии Platform V IAM SE 2.3.1

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Существует в открытом доступе

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 13%
0.00225
Низкий

6.9 Medium

CVSS3

6.1 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.9
ubuntu
4 месяца назад

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a prototype pollution-based XSS bypass. When an application uses `DOMPurify.sanitize()` with the default configuration (no `CUSTOM_ELEMENT_HANDLING` option), a prior prototype pollution gadget can inject permissive `tagNameCheck` and `attributeNameCheck` regex values into `Object.prototype`, causing DOMPurify to allow arbitrary custom elements with arbitrary attributes — including event handlers — through sanitization. Version 3.4.0 fixes the issue.

CVSS3: 6.8
redhat
4 месяца назад

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a prototype pollution-based XSS bypass. When an application uses `DOMPurify.sanitize()` with the default configuration (no `CUSTOM_ELEMENT_HANDLING` option), a prior prototype pollution gadget can inject permissive `tagNameCheck` and `attributeNameCheck` regex values into `Object.prototype`, causing DOMPurify to allow arbitrary custom elements with arbitrary attributes — including event handlers — through sanitization. Version 3.4.0 fixes the issue.

CVSS3: 6.9
nvd
4 месяца назад

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a prototype pollution-based XSS bypass. When an application uses `DOMPurify.sanitize()` with the default configuration (no `CUSTOM_ELEMENT_HANDLING` option), a prior prototype pollution gadget can inject permissive `tagNameCheck` and `attributeNameCheck` regex values into `Object.prototype`, causing DOMPurify to allow arbitrary custom elements with arbitrary attributes — including event handlers — through sanitization. Version 3.4.0 fixes the issue.

CVSS3: 6.9
debian
4 месяца назад

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathM ...

CVSS3: 6.9
github
4 месяца назад

DOMPurify: Prototype Pollution to XSS Bypass via CUSTOM_ELEMENT_HANDLING Fallback

EPSS

Процентиль: 13%
0.00225
Низкий

6.9 Medium

CVSS3

6.1 Medium

CVSS2