VDB
KO
CRITICAL 9.1

GHSA-p3vf-v8qc-cwcr

DOMPurify vulnerable to tampering by prototype polution

Details

dompurify was vulnerable to prototype pollution

Fixed by https://github.com/cure53/DOMPurify/commit/d1dd0374caef2b4c56c3bd09fe1988c3479166dc

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / dompurify
Introduced in: 0 Fixed in: 2.4.2
Fix npm install dompurify@2.4.2

References