Cross-site scripting in DOMPurify - #VU152599
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code in the victim page origin.
The vulnerability exists due to improper neutralization of input during web page generation in DOMPurify IN_PLACE sanitization when processing attacker-supplied markup with a node-removing afterSanitizeElements or afterSanitizeAttributes hook. A remote attacker can supply crafted markup containing an event handler in a descendant of a removed non-root element to execute arbitrary code in the victim page origin.