Unrated severityNVD Advisory· Published Jul 24, 2026
Debian node-dompurify: DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig…
CVE-2026-65898
Description
DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to permanently mutate the shared allowlist. Attackers can register a hook that conditionally allows dangerous attributes like onerror for trusted elements, then submit untrusted content that inherits the polluted allowlist and executes event handlers as stored XSS.
Affected products
2- Range: <3.4.11
Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.