Medium severity6.1NVD Advisory· Published Jul 23, 2026· Updated Jul 28, 2026
CVE-2026-65912
CVE-2026-65912
Description
DOMPurify before 3.3.2 contains a URI validation bypass vulnerability when ADD_ATTR is provided as a predicate function via EXTRA_ELEMENT_HANDLING.attributeCheck. Attackers can supply a predicate that accepts specific attribute and tag combinations to bypass URI-safe validation, allowing unsafe protocols like javascript: to survive sanitization and execute as DOM-based XSS when the link is activated.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dompurifynpm | < 3.3.2 | 3.3.2 |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-cjmm-f4jc-qw8rghsaADVISORY
- github.com/cure53/DOMPurify/security/advisories/GHSA-cjmm-f4jc-qw8rnvdThird Party AdvisoryWEB
- www.vulncheck.com/advisories/dompurify-before-uri-validation-bypass-via-add-attrnvdThird Party Advisory
- github.com/cure53/DOMPurify/releases/tag/3.3.2ghsaWEB
News mentions
0No linked articles in our index yet.