Cross-site scripting in DOMPurify - CVE-2026-49978
Published: May 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script in the victim's browser.
The vulnerability exists due to cross-site scripting in template content sanitization when processing HTML containing a template element with an attached shadow root inside template.content. A remote attacker can supply crafted HTML that survives sanitization to execute arbitrary script in the victim's browser.
Exploitation occurs when the application clones the template and inserts the result into the page.
Affected software
Ansible Automation Platform
Red Hat Advanced Cluster Security for Kubernetes
How to mitigate CVE-2026-49978
Ansible Automation Platform - update to 2.2.0
Red Hat Advanced Cluster Security for Kubernetes - update to 4.11.2