CVE-2026-65898
EUVD-2026-4828623.07.2026, 14:18
DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to permanently mutate the shared allowlist. Attackers can register a hook that conditionally allows dangerous attributes like onerror for trusted elements, then submit untrusted content that inherits the polluted allowlist and executes event handlers as stored XSS.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cure53 | dompurify | 𝑥 < 3.4.11 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases