Medium severity6.1NVD Advisory· Published Oct 7, 2020· Updated Jun 17, 2026
CVE-2020-26870
CVE-2020-26870
Description
Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dompurifynpm | < 2.0.17 | 2.0.17 |
Affected products
10- cpe:2.3:a:microsoft:visual_studio_2017:15.9:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2019:16.0:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:microsoft:visual_studio_2019:16.0:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:visual_studio_2019:16.4:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:visual_studio_2019:16.7:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:visual_studio_2019:16.8:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:application_express:*:*:*:*:*:*:*:*Range: <21.1.0.00.01
- Cure53/DOMPurifydescription
Patches
Vulnerability mechanics
References
10- github.com/cure53/DOMPurify/commit/02724b8eb048dd219d6725b05c3000936f11d62dnvdPatchThird Party AdvisoryWEB
- github.com/cure53/DOMPurify/compare/2.0.16...2.0.17nvdPatchThird Party AdvisoryWEB
- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-26870nvdPatchVendor AdvisoryWEB
- www.oracle.com//security-alerts/cpujul2021.htmlnvdPatchThird Party AdvisoryWEB
- research.securitum.com/mutation-xss-via-mathml-mutation-dompurify-2-0-17-bypass/nvdExploitThird Party Advisory
- github.com/advisories/GHSA-63q7-h895-m982ghsaADVISORY
- lists.debian.org/debian-lts-announce/2020/10/msg00029.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-26870ghsaADVISORY
- research.securitum.com/mutation-xss-via-mathml-mutation-dompurify-2-0-17-bypassghsaWEB
- snyk.io/vuln/SNYK-JS-DOMPURIFY-1016634ghsaWEB
News mentions
0No linked articles in our index yet.