๐Ÿ” CVE Alert

CVE-2026-75838

UNKNOWN 0.0

DOMPurify before 3.4.13 Cross-Site Scripting via IN_PLACE hook

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees. Attackers can supply HTML with event handlers on descendant elements that execute after sanitization completes, even though the returned root appears clean.

CWE CWE-79
Vendor cure53
Product dompurify
Published Aug 18, 2026
Last Updated Aug 18, 2026
Stay Ahead of the Next One

Get instant alerts for cure53 dompurify

Be the first to know when new unknown vulnerabilities affecting cure53 dompurify are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

cure53 / DOMPurify
0 < 3.4.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/cure53/DOMPurify/security/advisories/GHSA-55q2-fjhq-7xh7 vulncheck.com: https://www.vulncheck.com/advisories/dompurify-before-cross-site-scripting-via-in-place-hook

Credits

๐Ÿ” koyokr