VYPR
Unrated severityNVD Advisory· Published Jul 24, 2026

Debian node-dompurify: DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig…

CVE-2026-65898

Description

DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to permanently mutate the shared allowlist. Attackers can register a hook that conditionally allows dangerous attributes like onerror for trusted elements, then submit untrusted content that inherits the polluted allowlist and executes event handlers as stored XSS.

Affected products

2

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.