High severityNVD Advisory· Published Oct 11, 2024· Updated Nov 3, 2025
DOMPurify nesting-based mXSS
CVE-2024-47875
Description
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dompurifynpm | < 2.5.0 | 2.5.0 |
dompurifynpm | >= 3.0.0, < 3.1.3 | 3.1.3 |
Affected products
36- osv-coords35 versionspkg:apk/chainguard/argo-workflow-clipkg:apk/chainguard/argo-workflow-controllerpkg:apk/chainguard/argo-workflow-controller-compatpkg:apk/chainguard/argo-workflow-executorpkg:apk/chainguard/argo-workflow-executor-compatpkg:apk/chainguard/argo-workflowspkg:apk/chainguard/argo-workflows-known-hostspkg:apk/chainguard/argo-workflows-uipkg:apk/chainguard/opensearch-dashboards-2-fipspkg:apk/chainguard/opensearch-dashboards-2-fips-alerting-dashboards-pluginpkg:apk/chainguard/opensearch-dashboards-2-fips-anomaly-detection-dashboards-pluginpkg:apk/chainguard/opensearch-dashboards-2-fips-configpkg:apk/chainguard/opensearch-dashboards-2-fips-dashboards-mapspkg:apk/chainguard/opensearch-dashboards-2-fips-dashboards-notificationspkg:apk/chainguard/opensearch-dashboards-2-fips-dashboards-observabilitypkg:apk/chainguard/opensearch-dashboards-2-fips-dashboards-query-workbenchpkg:apk/chainguard/opensearch-dashboards-2-fips-dashboards-reportingpkg:apk/chainguard/opensearch-dashboards-2-fips-dashboards-search-relevancepkg:apk/chainguard/opensearch-dashboards-2-fips-dashboards-visualizationspkg:apk/chainguard/opensearch-dashboards-2-fips-index-management-dashboards-pluginpkg:apk/chainguard/opensearch-dashboards-2-fips-ml-commons-dashboardspkg:apk/chainguard/opensearch-dashboards-2-fips-security-analytics-dashboards-pluginpkg:apk/chainguard/opensearch-dashboards-2-fips-security-dashboards-pluginpkg:apk/wolfi/argo-workflow-clipkg:apk/wolfi/argo-workflow-controllerpkg:apk/wolfi/argo-workflow-controller-compatpkg:apk/wolfi/argo-workflow-executorpkg:apk/wolfi/argo-workflow-executor-compatpkg:apk/wolfi/argo-workflowspkg:apk/wolfi/argo-workflows-known-hostspkg:apk/wolfi/argo-workflows-uipkg:npm/dompurifypkg:rpm/almalinux/grafanapkg:rpm/almalinux/grafana-selinuxpkg:rpm/opensuse/velociraptor&distro=openSUSE%20Tumbleweed
< 3.6.0-r0+ 34 more
- (no CPE)range: < 3.6.0-r0
- (no CPE)range: < 3.6.0-r0
- (no CPE)range: < 3.6.0-r0
- (no CPE)range: < 3.6.0-r0
- (no CPE)range: < 3.6.0-r0
- (no CPE)range: < 3.6.0-r0
- (no CPE)range: < 3.6.0-r0
- (no CPE)range: < 3.6.0-r0
- (no CPE)range: < 2.17.1-r0
- (no CPE)range: < 2.17.1-r0
- (no CPE)range: < 2.17.1-r0
- (no CPE)range: < 2.17.1-r0
- (no CPE)range: < 2.17.1-r0
- (no CPE)range: < 2.17.1-r0
- (no CPE)range: < 2.17.1-r0
- (no CPE)range: < 2.17.1-r0
- (no CPE)range: < 2.17.1-r0
- (no CPE)range: < 2.17.1-r0
- (no CPE)range: < 2.17.1-r0
- (no CPE)range: < 2.17.1-r0
- (no CPE)range: < 2.17.1-r0
- (no CPE)range: < 2.17.1-r0
- (no CPE)range: < 2.17.1-r0
- (no CPE)range: < 3.6.0-r0
- (no CPE)range: < 3.6.0-r0
- (no CPE)range: < 3.6.0-r0
- (no CPE)range: < 3.6.0-r0
- (no CPE)range: < 3.6.0-r0
- (no CPE)range: < 3.6.0-r0
- (no CPE)range: < 3.6.0-r0
- (no CPE)range: < 3.6.0-r0
- (no CPE)range: < 2.5.0
- (no CPE)range: < 9.2.10-20.el8_10
- (no CPE)range: < 9.2.10-20.el8_10
- (no CPE)range: < 0.7.0.4.git142.862ef23-1.1
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-gx9m-whjm-85jfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-47875ghsaADVISORY
- seclists.org/fulldisclosure/2025/Apr/14ghsaWEB
- github.com/cure53/DOMPurify/blob/0ef5e537a514f904b6aa1d7ad9e749e365d7185f/test/test-suite.jsghsax_refsource_MISCWEB
- github.com/cure53/DOMPurify/commit/0ef5e537a514f904b6aa1d7ad9e749e365d7185fghsax_refsource_MISCWEB
- github.com/cure53/DOMPurify/commit/6ea80cd8b47640c20f2f230c7920b1f4ce4fdf7aghsax_refsource_MISCWEB
- github.com/cure53/DOMPurify/security/advisories/GHSA-gx9m-whjm-85jfghsax_refsource_CONFIRMWEB
- lists.debian.org/debian-lts-announce/2025/02/msg00010.htmlghsaWEB
News mentions
0No linked articles in our index yet.