CVE-2026-75838
DOMPurify before 3.4.13 Cross-Site Scripting via IN_PLACE hook
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees. Attackers can supply HTML with event handlers on descendant elements that execute after sanitization completes, even though the returned root appears clean.
| CWE | CWE-79 |
| Vendor | cure53 |
| Product | dompurify |
| Published | Aug 18, 2026 |
| Last Updated | Aug 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for cure53 dompurify
Be the first to know when new unknown vulnerabilities affecting cure53 dompurify are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
cure53 / DOMPurify
0 < 3.4.13
References
Credits
๐ koyokr