CVE-2026-65898: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in cure53 DOMPurify
DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to permanently mutate the shared allowlist. Attackers can register a hook that conditionally allows dangerous attributes like onerror for trusted elements, then submit untrusted content that inherits the polluted allowlist and executes event handlers as stored XSS.
AI Analysis
Technical Summary
DOMPurify before version 3.4.11 fails to clone the ALLOWED_ATTR allowlist when the setConfig() method is used alongside an uponSanitizeAttribute hook. This improper neutralization allows the hook to mutate the shared allowlist permanently. An attacker can exploit this by registering a hook that conditionally permits dangerous attributes such as onerror for trusted elements. Subsequently, when untrusted content is sanitized, it inherits the polluted allowlist, enabling execution of event handlers as stored cross-site scripting (XSS). This vulnerability affects DOMPurify versions prior to 3.4.11.
Potential Impact
An attacker can exploit this vulnerability to execute stored cross-site scripting attacks by injecting malicious event handlers into sanitized content. This can lead to the execution of arbitrary scripts in the context of the affected web application, potentially compromising user data or session integrity. The issue arises from the permanent mutation of the shared allowlist, which undermines the sanitization process.
Mitigation Recommendations
Upgrade DOMPurify to version 3.4.11 or later, where this vulnerability is fixed by properly cloning the ALLOWED_ATTR allowlist when using setConfig() with an uponSanitizeAttribute hook. No other mitigation is recommended as the fix addresses the root cause.
CVE-2026-65898: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in cure53 DOMPurify
Description
DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to permanently mutate the shared allowlist. Attackers can register a hook that conditionally allows dangerous attributes like onerror for trusted elements, then submit untrusted content that inherits the polluted allowlist and executes event handlers as stored XSS.
CVSS v4.0
Score 5.1medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
DOMPurify before version 3.4.11 fails to clone the ALLOWED_ATTR allowlist when the setConfig() method is used alongside an uponSanitizeAttribute hook. This improper neutralization allows the hook to mutate the shared allowlist permanently. An attacker can exploit this by registering a hook that conditionally permits dangerous attributes such as onerror for trusted elements. Subsequently, when untrusted content is sanitized, it inherits the polluted allowlist, enabling execution of event handlers as stored cross-site scripting (XSS). This vulnerability affects DOMPurify versions prior to 3.4.11.
Potential Impact
An attacker can exploit this vulnerability to execute stored cross-site scripting attacks by injecting malicious event handlers into sanitized content. This can lead to the execution of arbitrary scripts in the context of the affected web application, potentially compromising user data or session integrity. The issue arises from the permanent mutation of the shared allowlist, which undermines the sanitization process.
Mitigation Recommendations
Upgrade DOMPurify to version 3.4.11 or later, where this vulnerability is fixed by properly cloning the ALLOWED_ATTR allowlist when using setConfig() with an uponSanitizeAttribute hook. No other mitigation is recommended as the fix addresses the root cause.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-23T11:03:13.092Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a6215a29c2644c7f82072c7
Added to database: 07/23/2026, 13:22:42 UTC
Last enriched: 07/23/2026, 13:40:39 UTC
Last updated: 07/24/2026, 03:47:26 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.