Medium severity6.1NVD Advisory· Published Jul 24, 2026· Updated Aug 6, 2026
CVE-2026-66010
CVE-2026-66010
Description
DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive attributes on custom elements that later re-inject them into innerHTML sinks, creating second-order XSS gadgets.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3(expand)+ 1 more
- (no CPE)
- (no CPE)
Package: https://rubygems.org/gems/dompurify
Patches
Vulnerability mechanics
References
2- github.com/cure53/DOMPurify/security/advisories/GHSA-c2j3-45gr-mqc4nvdExploitVendor Advisory
- www.vulncheck.com/advisories/dompurify-before-hook-bypass-via-custom-element-handlingnvdThird Party Advisory
News mentions
0No linked articles in our index yet.