Cross-site scripting in DOMPurify - #VU152600
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script.
The vulnerability exists due to improper neutralization of rawtext text content in the DOMPurify IN_PLACE return path when serializing and reparsing a force-removed rawtext root in plain HTML context. A remote attacker can provide a crafted rawtext node to execute arbitrary script.
Moving the returned node with appendChild alone does not trigger the payload.