VDB
KO
MEDIUM 6.1

GHSA-8hgg-xxm5-3873

DOMPurify Open Redirect vulnerability

Details

DOMPurify before 1.0.11 allows reverse tabnabbing in demos/hooks-target-blank-demo.html because links lack a 'rel="noopener noreferrer"' attribute.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / dompurify
Introduced in: 0 Fixed in: 1.0.11
Fix npm install dompurify@1.0.11

References