Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-49459

Опубликовано: 14 июл. 2026
Источник: redhat
CVSS3: 4.7

Описание

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on an attacker-controlled

root when a descendant name clobbered properties checked by _isClobbered, because _forceRemove no-opped on the parent-less root and _sanitizeAttributes returned early. This issue is fixed in version 3.4.6.

A flaw was found in DOMPurify, a library designed to sanitize HTML, MathML, and SVG to prevent cross-site scripting (XSS) attacks. A remote attacker could exploit a vulnerability in the DOMPurify.sanitize function when used with the IN_PLACE: true option. This flaw allows an attacker to bypass the sanitizer and inject malicious event-handler attributes into an attacker-controlled form element. Successful exploitation could lead to the execution of arbitrary scripts in the user's browser, potentially compromising user data or session integrity.

Отчет

This Moderate-impact cross-site scripting (XSS) bypass in DOMPurify arises when the DOMPurify.sanitize function is invoked with the IN_PLACE: true option on an attacker-controlled HTML form element. Successful exploitation requires a specific application configuration where untrusted HTML is processed in this manner, allowing malicious event handlers to persist and execute arbitrary scripts. Red Hat products are generally not affected by default configurations, as this specific usage pattern is uncommon.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-console-plugin-rhel9Fix deferred
Migration Toolkit for Virtualizationmtv-candidate/mtv-console-plugin-rhel9Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel9Under investigation
Node HealthCheck Operatorworkload-availability/node-healthcheck-must-gather-rhel9Fix deferred
Node HealthCheck Operatorworkload-availability/node-healthcheck-operator-bundleFix deferred
Node HealthCheck Operatorworkload-availability/node-healthcheck-rhel9-operatorFix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-agentic-console-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-console-plugin-419-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-console-plugin-pf5-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-console-plugin-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2500676dompurify: DOMPurify: Cross-site scripting bypass allows arbitrary script execution

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
23 дня назад

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on an attacker-controlled <form> root when a descendant name clobbered properties checked by _isClobbered, because _forceRemove no-opped on the parent-less root and _sanitizeAttributes returned early. This issue is fixed in version 3.4.6.

CVSS3: 6.1
nvd
23 дня назад

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on an attacker-controlled <form> root when a descendant name clobbered properties checked by _isClobbered, because _forceRemove no-opped on the parent-less root and _sanitizeAttributes returned early. This issue is fixed in version 3.4.6.

CVSS3: 6.1
debian
23 дня назад

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathM ...

CVSS3: 6.1
github
около 2 месяцев назад

DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM

4.7 Medium

CVSS3