Update dependency dompurify to v3 [SECURITY] - #36
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/npm-dompurify-vulnerability
branch
from
October 9, 2024 08:00
9191272 to
842f8cf
Compare
renovate
Bot
force-pushed
the
renovate/npm-dompurify-vulnerability
branch
from
January 23, 2025 18:08
842f8cf to
e584b80
Compare
renovate
Bot
force-pushed
the
renovate/npm-dompurify-vulnerability
branch
from
February 14, 2025 19:26
e584b80 to
44be7e0
Compare
renovate
Bot
force-pushed
the
renovate/npm-dompurify-vulnerability
branch
from
August 10, 2025 12:50
44be7e0 to
7685d12
Compare
renovate
Bot
force-pushed
the
renovate/npm-dompurify-vulnerability
branch
from
September 25, 2025 18:29
7685d12 to
7d31167
Compare
renovate
Bot
force-pushed
the
renovate/npm-dompurify-vulnerability
branch
from
October 21, 2025 16:02
7d31167 to
f447b8a
Compare
renovate
Bot
force-pushed
the
renovate/npm-dompurify-vulnerability
branch
from
December 31, 2025 15:03
f447b8a to
a37445f
Compare
renovate
Bot
force-pushed
the
renovate/npm-dompurify-vulnerability
branch
from
March 5, 2026 15:05
a37445f to
07a1428
Compare
renovate
Bot
force-pushed
the
renovate/npm-dompurify-vulnerability
branch
from
March 13, 2026 16:15
07a1428 to
c7fc78c
Compare
renovate
Bot
force-pushed
the
renovate/npm-dompurify-vulnerability
branch
2 times, most recently
from
March 28, 2026 05:02
c7fc78c to
f53b484
Compare
renovate
Bot
force-pushed
the
renovate/npm-dompurify-vulnerability
branch
from
April 16, 2026 08:36
f53b484 to
4c928b6
Compare
renovate
Bot
force-pushed
the
renovate/npm-dompurify-vulnerability
branch
from
May 1, 2026 16:14
4c928b6 to
8117df6
Compare
renovate
Bot
force-pushed
the
renovate/npm-dompurify-vulnerability
branch
from
May 18, 2026 10:46
8117df6 to
3f9232f
Compare
renovate
Bot
force-pushed
the
renovate/npm-dompurify-vulnerability
branch
from
May 28, 2026 15:43
3f9232f to
e2b0af5
Compare
renovate
Bot
force-pushed
the
renovate/npm-dompurify-vulnerability
branch
2 times, most recently
from
June 16, 2026 07:59
9012dc4 to
b85ab83
Compare
renovate
Bot
force-pushed
the
renovate/npm-dompurify-vulnerability
branch
from
June 20, 2026 09:17
b85ab83 to
25fef1e
Compare
|
Tick the box to add this pull request to the merge queue (same as
|
renovate
Bot
force-pushed
the
renovate/npm-dompurify-vulnerability
branch
from
July 12, 2026 11:35
25fef1e to
4494d67
Compare
|
Tick the box to add this pull request to the merge queue (same as
|
2 similar comments
|
Tick the box to add this pull request to the merge queue (same as
|
|
Tick the box to add this pull request to the merge queue (same as
|
renovate
Bot
force-pushed
the
renovate/npm-dompurify-vulnerability
branch
from
August 9, 2026 05:12
4494d67 to
f126413
Compare
|
Tick the box to add this pull request to the merge queue (same as
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^2.0.8→^3.0.0DOMPurify allows tampering by prototype pollution
CVE-2024-45801 / GHSA-mmhx-hmjr-r674
More information
Details
It has been discovered that malicious HTML using special nesting techniques can bypass the depth checking added to DOMPurify in recent releases. It was also possible to use Prototype Pollution to weaken the depth check.
This renders dompurify unable to avoid XSS attack.
Fixed by cure53/DOMPurify@1e52026 (3.x branch) and cure53/DOMPurify@26e1d69 (2.x branch).
Severity
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
DOMpurify has a nesting-based mXSS
CVE-2024-47875 / GHSA-gx9m-whjm-85jf
More information
Details
DOMpurify was vulnerable to nesting-based mXSS
fixed by 0ef5e537 (2.x) and
merge 943
Backporter should be aware of GHSA-mmhx-hmjr-r674 (CVE-2024-45801) when cherry-picking
POC is avaible under test
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
DOMPurify vulnerable to tampering by prototype polution
CVE-2024-48910 / GHSA-p3vf-v8qc-cwcr
More information
Details
dompurify was vulnerable to prototype pollution
Fixed by cure53/DOMPurify@d1dd037
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
DOMPurify allows Cross-site Scripting (XSS)
CVE-2025-26791 / GHSA-vhxf-7vqr-mrjg
More information
Details
DOMPurify before 3.2.4 has an incorrect template literal regular expression when SAFE_FOR_TEMPLATES is set to true, sometimes leading to mutation cross-site scripting (mXSS).
Severity
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
DOMPurify is vulnerable to mutation-XSS via Re-Contextualization
CVE-2026-65914 / GHSA-h8r8-wccr-v5f2
More information
Details
Description
A mutation-XSS (mXSS) condition was confirmed when sanitized HTML is reinserted into a new parsing context using
innerHTMLand special wrappers. The vulnerable wrappers confirmed in browser behavior arescript,xmp,iframe,noembed,noframes, andnoscript. The payload remains seemingly benign afterDOMPurify.sanitize(), but mutates during the second parse into executable markup with an event handler, enabling JavaScript execution in the client (alert(1)in the PoC).Vulnerability
The root cause is context switching after sanitization: sanitized output is treated as trusted and concatenated into a wrapper string (for example,
<xmp> ... </xmp>or other special wrappers) before being reparsed by the browser. In this flow, attacker-controlled text inside an attribute (for example</xmp>or equivalent closing sequences for each wrapper) closes the special parsing context early and reintroduces attacker markup (<img ... onerror=...>) outside the original attribute context. DOMPurify sanitizes the original parse tree, but the application performs a second parse in a different context, reactivating dangerous tokens (classic mXSS pattern).PoC
http://localhost:3001.Wrapper en sinktoxmp.Sanitize + Render.Sanitized responsestill contains the</xmp>sequence insidealt.<img src="x" onerror="alert('expoc')">.alert('expoc')is triggered.{ "name": "expoc", "version": "1.0.0", "main": "server.js", "scripts": { "test": "echo \"Error: no test specified\" && exit 1", "start": "node server.js", "dev": "node server.js" }, "keywords": [], "author": "", "license": "ISC", "description": "", "dependencies": { "dompurify": "^3.3.1", "express": "^5.2.1", "jsdom": "^28.1.0" } }Evidence
daft-video.webm
Why This Happens
This is a mutation-XSS pattern caused by a parse-context mismatch:
xmpraw-text behavior).</xmp>) gains structural meaning in parse 2 and alters DOM structure.Sanitization is not a universal guarantee across all future parsing contexts. The sink design reintroduces risk.
Remediation Guidance
innerHTML.textContent,createElement,setAttribute) over string-based HTML composition.xmp,script, etc.).</xmp>,</noscript>, similar parser-breakout markers).Reported by Oscar Uribe, Security Researcher at Fluid Attacks. Camilo Vera and Cristian Vargas from the Fluid Attacks Research Team have identified a mXSS via Re-Contextualization in DomPurify 3.3.1.
Following Fluid Attacks Disclosure Policy, if this report corresponds to a vulnerability and the conditions outlined in the policy are met, this advisory will be published on the website over the next few days (the timeline may vary depending on maintainers' willingness to attend to and respond to this report) at the following URL: https://fluidattacks.com/advisories/daft
Acknowledgements: Camilo Vera and Cristian Vargas.
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
DOMPurify USE_PROFILES prototype pollution allows event handlers
CVE-2026-65913 / GHSA-cj63-jhhr-wcxv
More information
Details
Summary
When
USE_PROFILESis enabled, DOMPurify rebuildsALLOWED_ATTRas a plain array before populating it with the requested allowlists. Because the sanitizer still looks up attributes viaALLOWED_ATTR[lcName], anyArray.prototypeproperty that is polluted also counts as an allowlisted attribute. An attacker who can setArray.prototype.onclick = true(or a runtime already subject to prototype pollution) can thus force DOMPurify to keep event handlers such asonclickeven when they are normally forbidden. The provided PoC sanitizes<img onclick=...>withUSE_PROFILESand adds the sanitized output to the DOM; the polluted prototype allows the event handler to survive and execute, turning what should be a blocklist into a silent XSS vector.Impact
Prototype pollution makes DOMPurify accept dangerous event handler attributes, which bypasses the sanitizer and results in DOM-based XSS once the sanitized markup is rendered.
Credits
Identified by Cantina’s Apex (https://www.cantina.security).
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
DOMPurify ADD_ATTR predicate skips URI validation
CVE-2026-65912 / GHSA-cjmm-f4jc-qw8r
More information
Details
Summary
DOMPurify allows
ADD_ATTRto be provided as a predicate function viaEXTRA_ELEMENT_HANDLING.attributeCheck. When the predicate returnstrue,_isValidAttributeshort-circuits the attribute check before URI-safe validation runs. An attacker who supplies a predicate that accepts specific attribute/tag combinations can then sanitize input such as<a href="javascript:alert(document.domain)">and have thejavascript:URL survive, because URI validation is skipped for that attribute while other checks still pass. The provided PoC acceptshreffor anchors and then triggers a click inside an iframe, showing that the sanitized payload executes despite the protocol bypass.Impact
Predicate-based allowlisting bypasses DOMPurify's URI validation, allowing unsafe protocols such as
javascript:to reach the DOM and execute whenever the link is activated, resulting in DOM-based XSS.Credits
Identified by Cantina’s Apex (https://www.cantina.security).
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation
CVE-2026-65903 / GHSA-39q2-94rc-95cp
More information
Details
Summary
In
src/purify.ts:1117-1123,ADD_TAGSas a function (viaEXTRA_ELEMENT_HANDLING.tagCheck) bypassesFORBID_TAGSdue to short-circuit evaluation.The condition:
When
tagCheck(tagName)returnstrue, the entire condition isfalseand the element is kept —FORBID_TAGS[tagName]is never evaluated.Inconsistency
This contradicts the attribute-side pattern at line 1214 where
FORBID_ATTRexplicitly wins first:For tags, FORBID should also take precedence over ADD.
Impact
Applications using both
ADD_TAGSas a function andFORBID_TAGSsimultaneously get unexpected behavior — forbidden tags are allowed through. Config-dependent but a genuine logic inconsistency.Suggested Fix
Check
FORBID_TAGSbeforetagCheck:Affected Version
v3.3.3 (commit 883ac15)
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
DOMPurify has a SAFE_FOR_TEMPLATES bypass in RETURN_DOM mode
CVE-2026-41239 / GHSA-crv5-9vww-q3g8
More information
Details
Summary
mainat883ac15, introduced in v1.0.10 (7fc196db)SAFE_FOR_TEMPLATESstrips{{...}}expressions from untrusted HTML. This works in string mode but not withRETURN_DOMorRETURN_DOM_FRAGMENT, allowing XSS via template-evaluating frameworks like Vue 2.Technical Details
DOMPurify strips template expressions in two passes:
purify.ts:1179-1191):purify.ts:1679-1683). This is the safety net that catches expressions that only form after the DOM settles.The
RETURN_DOMpath returns before pass #2 ever runs (purify.ts:1637-1661):The payload
{<foo></foo>{constructor.constructor('alert(1)')()}<foo></foo>}exploits this:TEXT("{")→<foo>→TEXT("{payload}")→<foo>→TEXT("}")— no single node contains{{, so pass #1 misses it<foo>is not allowed, so DOMPurify removes it but keeps surrounding text.outerHTMLreads them as{{payload}}, which Vue 2 compiles and executesReproduce
Open the following html in any browser and
alert(1)pops up.Impact
Any application that sanitizes attacker-controlled HTML with
SAFE_FOR_TEMPLATES: trueandRETURN_DOM: true(orRETURN_DOM_FRAGMENT: true), then mounts the result into a template-evaluating framework, is vulnerable to XSS.Recommendations
Fix
normalize()merges the split text nodes, then the same regex from the string path catches the expression. Placed before the fragment logic, this fixes bothRETURN_DOMandRETURN_DOM_FRAGMENT.if (RETURN_DOM) { + if (SAFE_FOR_TEMPLATES) { + body.normalize(); + let html = body.innerHTML; + arrayForEach([MUSTACHE_EXPR, ERB_EXPR, TMPLIT_EXPR], (expr: RegExp) => { + html = stringReplace(html, expr, ' '); + }); + body.innerHTML = html; + } + if (RETURN_DOM_FRAGMENT) { returnNode = createDocumentFragment.call(body.ownerDocument);Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
DOMPurify: FORBID_TAGS bypassed by function-based ADD_TAGS predicate (asymmetry with FORBID_ATTR fix)
CVE-2026-41240 / GHSA-h7mw-gpvr-xq4m
More information
Details
There is an inconsistency between FORBID_TAGS and FORBID_ATTR handling when function-based ADD_TAGS is used.
Commit c361baa added an early exit for FORBID_ATTR at line 1214:
The same fix was not applied to FORBID_TAGS. At line 1118-1123, when EXTRA_ELEMENT_HANDLING.tagCheck returns true, the short-circuit evaluation skips the FORBID_TAGS check entirely:
This allows forbidden elements to survive sanitization with their attributes intact.
PoC (tested against current HEAD in Node.js + jsdom):
Confirmed affected: iframe, object, embed, form. The src/action/data attributes survive because attribute sanitization runs separately and allows these URLs.
Compare with FORBID_ATTR which correctly wins:
Suggested fix: add FORBID_TAGS early exit before the tagCheck evaluation, mirroring line 1214:
This requires function-based ADD_TAGS in the config, which is uncommon. But the asymmetry with the FORBID_ATTR fix is clear, and the impact includes iframe and form injection with external URLs.
Reporter: Koda Reef
Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM
CVE-2026-49459 / GHSA-r47g-fvhr-h676
More information
Details
IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM
CWE: CWE-79 (XSS — Improper Neutralization of Input During Web Page Generation) via CWE-693 (Protection Mechanism Failure — silent no-op when
_forceRemoveis called on a parent-less node)Summary
When
DOMPurify.sanitize(root, { IN_PLACE: true })is called androotis a<form>whose own attributes carry an event handler (onmouseover,onfocus,onclick, etc.), a single descendant element with aname=attribute matching any of the property names_isClobberedchecks (nodeName,setAttribute,namespaceURI,insertBefore,hasChildNodes,childNodes) is sufficient to bypass attribute sanitization on the root._forceRemovesilently no-ops because the root has no parent; the iterator drives on to_sanitizeAttributes, which early-returns on clobbered nodes — and the event handler attribute is never inspected. The sanitized return is the same root, with the handler live.This affects current
mainat89da34e(the just-landed DOM-clobbering hardening fix at89da34eaddressed_sanitizeAttachedShadowRootswalk traversal, not the main_sanitizeElements/_sanitizeAttributespipeline against the iterator-root node).Affected
mainat89da34e03ec17868e561f87f3747a9371b61a9e7DOMPurify.sanitize(node, { IN_PLACE: true })wherenodeis built from untrusted HTML (e.g., parsed viacreateElement('template').innerHTML = dirtythentemplate.content.firstElementChildhanded in)Not affected:
DOMPurify.sanitize(dirtyString)— the library builds the DOM itself inside_initDocument, the root is the cleanly-created document body, and clobber-named children of the body cannot shadowbodynamed properties (HTMLBodyElement does not carry[LegacyOverrideBuiltIns])Vulnerability details
Code paths
[A] —
_forceRemoveatsrc/purify.ts:930-939:When the iterator-root has no parent (the standard IN_PLACE case where the caller hands in a detached node),
getParentNode(node)returnsnull,null.removeChild(node)throws, the catch falls toremove(node)— which per WebIDL isElement.prototype.remove.call(node), and per spec does nothing if the node has no parent. Nothing about_forceRemove's contract acknowledges this — the function appears to its callers as "the node is gone now," but the node is still in place.[B] —
_sanitizeAttributesatsrc/purify.ts:1490-1492:The skip at
[B]is deliberate — the intent is to avoid touching nodes the library has already decided to discard. The invariant the comment implies is "if_isClobbered, then_sanitizeElementsalready removed this node, so we will never reach_sanitizeAttributeson it." That invariant holds for every non-root node (their_forceRemovesucceeds in detaching them), but fails for the iterator root in IN_PLACE mode.The mismatch is between [A] and [B]: [A] assumes "removal" means the node will not be observed again, and [B] assumes any clobbered node it sees has already been removed. Neither holds for the iterator root. A correct guard would either make
_forceRemovefail loudly on parent-less nodes (so the caller can bail out of IN_PLACE entirely) or have_sanitizeAttributesstrip attributes from clobbered roots before returning.Iterator call site
src/purify.ts:1850-1864ignores the boolean return value of_sanitizeElements:If the return value were checked and
_sanitizeAttributesskipped when the node was "killed," the bug would not exist as a discrete issue — but currently_sanitizeAttributesis the only line of defense for a node that_sanitizeElementscould not actually detach.Why the clobber works
In Chromium/WebKit/Firefox,
HTMLFormElementcarries the WebIDL[LegacyOverrideBuiltIns]extended attribute on its named-property getter. A descendant element withname="X"(orid="X", for radio-button-like names) shadows the matching property on the form, including properties inherited fromElement,Node, andEventTargetprototypes. This is the same primitive the just-landed89da34efix addresses for shadow-root traversal, but_isClobbered's typeof checks (and the bypass-by-detection-failure path here) are independent of that fix.Verified clobber targets (each name= value independently triggers
_isClobbered):name=value_isClobberedchecksnodeNametypeof element.nodeName !== 'string'<INPUT>)setAttributetypeof element.setAttribute !== 'function'<embed>/<applet>/<iframe>ARE callable; see "Note on callable elements" belownamespaceURItypeof element.namespaceURI !== 'string'insertBeforetypeof element.insertBefore !== 'function'hasChildNodestypeof element.hasChildNodes !== 'function'childNodes!(element.childNodes && typeof element.childNodes.length === 'number')<INPUT>has no.lengthattributes!(element.attributes instanceof NamedNodeMap)<INPUT>is not a NamedNodeMap)textContenttypeof element.textContent !== 'string'removeChildtypeof element.removeChild !== 'function'removeAttributetypeof element.removeAttribute !== 'function'Any single one of the ten property names in
_isClobbered's checklist is sufficient as the bypass trigger.Proof of concept
(1) Minimal — runnable in a single browser context
(2) End-to-end — Playwright against
mainHEADObserved (Chromium 148.0.7778.96, DOMPurify 3.4.5, HEAD
89da34e):(3) Variant matrix — six distinct clobber-target properties
Every property name in
_isClobbered's typeof checklist works as the bypass trigger:This makes the fix less of a one-line patch — every property
_isClobberedchecks for the typeof-spoofing pattern needs to be considered.Impact
Direct
Two distinct impact paths from the same root-attribute-survival primitive:
(a) XSS via event-handler attribute on the surviving root. Any consumer that uses
DOMPurify.sanitize(node, { IN_PLACE: true })wherenodeoriginated from untrusted HTML and is re-inserted into the live document is vulnerable to XSS. The typical pattern is:If
untrustedHtmlis<form onmouseover=…><input name=nodeName>…</form>, the resulting node has theonmouseoverattribute intact when re-inserted into the live document.(b) Every attribute-level defense is bypassed on the surviving root, not just event handlers. The
_sanitizeAttributesearly-return at:1490skips the entire attribute walk for clobbered nodes, so the root preserves attributes that the attribute walk would otherwise sanitize. Verified additional attributes that survive:action="javascript:..."andformaction="javascript:..."— URI validation at:1413never runs. A user click on a submit button inside the sanitized form navigates to thejavascript:URL, executing the handler. Adds a click-triggered XSS path on top of the mouseover/focus event-handler attributes already documented.id="<colliding-name>"— the DOM-clobbering guard at:1352-1359(SANITIZE_DOM && (lcName === 'id' || lcName === 'name') && (value in document || value in formElement)) lives inside_sanitizeAttributesand is skipped. An attacker can therefore landid="cookie",id="body",id="head",id="firstChild", etc. on the surviving form root and use it as a DOM-clobbering primitive against any consumer code that doesdocument.cookie,document.body, etc.target="_top",autofocus,formenctype,formmethod— all survive untouched.oncontentvisibilityautostatechange) survive on the clobbered root via the same skip; the per-name allow-list at:1361-1364never runs.Verified — full attribute set survives on a single payload (PoC):
(c) Defense-in-depth re-sanitization on the same node is INEFFECTIVE — the clobber is sticky. Chromium's
HTMLFormElementnamed-property cache appears to retain the named child reference even after the child'snameattribute is removed during the sanitization pass. Empirically verified — after the first sanitize pass, the input'sname="nodeName"attribute is correctly stripped (the output shows<input>with no attributes), yettypeof form.nodeName === 'object'is still true and the input element is still returned. CallingDOMPurify.sanitize(sameNode, { IN_PLACE: true })a second time hits the same_isClobbered→_forceRemove→_sanitizeAttributesearly-return path. The only effective recovery is serialize-then-reparse:A "belt-and-suspenders" caller that re-runs DOMPurify on its own output is therefore not protected against this primitive on Chromium; the obvious mitigation pattern fails silently. Any user-side workaround needs to route through a string round-trip.
(d) SAFE_FOR_TEMPLATES bypass for the root's attributes. When the caller sets
SAFE_FOR_TEMPLATES: trueto defend a downstream template engine (Vue, Angular, Liquid, Handlebars, …) from receiving `` /<%…%>/ `${…}` syntax through DOMPurify's output, attribute-level template-syntax stripping runs in the same `_sanitizeAttributes` pass that early-returns on clobbered roots (`:1572-1576`). The root's attributes therefore retain raw template syntax that the downstream engine then evaluates.Verified — same PoC structure, with
SAFE_FOR_TEMPLATES: true:This compounds with (a): a single payload exfiltrates via XSS (immediate) and via SSTI to downstream renderers (delayed).
(Text-node content inside the form is still scrubbed correctly —
_scrubTemplateExpressionsat:1868-1870walks text/comment/CDATA/PI nodes independently and reaches them via the iterator. Only attribute values on the clobbered root escape.)Indirect / second-order
el.innerHTML = …; DOMPurify.sanitize(el, { IN_PLACE: true }). The outerelis fine (it's not the form), but if the first child ofelis taken as the sanitization root in a different code path, the bypass triggers.Why current
mainis also vulnerableCommit
89da34e("fix: fixed a possible DOM clobbering with IN_PLACE and shadow DOM") hardens_sanitizeAttachedShadowRootsvia three new cached prototype getters (getShadowRoot,getNodeName,getNodeType) and an_isClobberedextension that checkselement.childNodes.length. The fix is correct for its scope — shadow-root traversal — but does not change_forceRemove's parent-less-node behavior or_sanitizeAttributes's clobber-skip early-return. The bypass demonstrated here is in the IN_PLACE main pipeline, not the shadow-root walk, and the verification PoC above runs against HEAD89da34eand still succeeds.Suggested fix
Two minimal-risk options:
Make
_forceRemovehonest about failure: return whether the node was actually detached, and have the iterator call site honor that.Then at
:1855, if_sanitizeElementsreturns true AND IN_PLACE, force-strip all attributes of the root before returning the dirty tree. (This is what the user expects — sanitization either succeeds or refuses to return a "sanitized" handle to an unsanitized tree.)Strip attributes inside
_sanitizeAttributesfor clobbered roots: when_isClobbered(currentNode)is true at:1490, instead of early-returning, iteratecurrentNode.attributes(using the cachedgetAttributesif you add one) and remove each viaremoveAttribute. This preserves the existing semantics for non-root clobbered nodes (their attributes-of-a-removed-node will be GC'd anyway) and removes the attack surface for root.Refuse IN_PLACE on parent-less clobbered roots: at the top of the iterator, check that the root either has a parent OR is not
_isClobbered. If both fail, throw. This is the most defensive option but breaks any existing caller that hands in a clobbered detached root expecting "sanitized = empty/safe."Note on callable elements
In Chromium and WebKit,
HTMLEmbedElement,HTMLAppletElement,HTMLIFrameElement, andHTMLScriptElementhavetypeof === 'function'because they expose plugin/iframe[[Call]]traps at the WebIDL level. Aname="setAttribute"child of one of these tags spoofs thesetAttribute typeof === 'function'check — but only matters for the attribute re-set path at:1619, not the bypass demonstrated here (which usesnodeNameand friends). The callable-element vector is worth checking separately as a potentialSAFE_FOR_TEMPLATES-bypass primitive; the present report does not depend on it.Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound
instanceofchecksCVE-2026-49458 / GHSA-hpcv-96wg-7vj8
More information
Details
Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound
instanceofchecksCWE: CWE-79 (XSS — Improper Neutralization of Input During Web Page Generation) via CWE-693 (Protection Mechanism Failure — realm-bound
instanceofchecks fail-open on foreign-realm DOM nodes) and CWE-501 (Trust Boundary Violation — foreign-realm nodes accepted for sanitization but later checks are bound to the parent realm)Summary
DOMPurify.sanitize(node, { IN_PLACE: true })accepts a DOM node from any same-origin realm (e.g. a node owned by an application-created iframe document), but several follow-on security checks compare the node against constructors from the parent realm. Because constructors are per-realm,instanceof HTMLFormElement,instanceof NamedNodeMap,instanceof DocumentFragment, andinstanceof Elementall returnfalsefor nodes belonging to the iframe's realm. The library therefore proceeds as if the foreign-realm form is not clobberable, the foreign-realm<template>'s.contentis not a document fragment, and the foreign-realm attached shadow root is not a document fragment — silently skipping the clobber/template-content/shadow-DOM sanitization branches that those checks gate. Attacker-controlled markup survives in form attributes, template content, and attached shadow roots, and executes when the application later inserts or activates the sanitized node.Affected
mainat89da34e03ec17868e561f87f3747a9371b61a9e7