VDB
Sign up
CRITICAL10.0

GHSA-gx9m-whjm-85jf

DOMpurify has a nesting-based mXSS

Quick fix

GHSA-gx9m-whjm-85jf — dompurify: upgrade to the fixed version with the command below.

npm install dompurify@2.5.0

Details

DOMpurify was vulnerable to nesting-based mXSS

fixed by [0ef5e537](https://github.com/cure53/DOMPurify/tree/0ef5e537a514f904b6aa1d7ad9e749e365d7185f) (2.x) and [merge 943](https://github.com/cure53/DOMPurify/pull/943)

Backporter should be aware of GHSA-mmhx-hmjr-r674 (CVE-2024-45801) when cherry-picking

POC is avaible under [test](https://github.com/cure53/DOMPurify/blob/0ef5e537a514f904b6aa1d7ad9e749e365d7185f/test/test-suite.js#L2098)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/dompurify
Introduced in: 0Fixed in: 2.5.0
Fixnpm install dompurify@2.5.0
npm/dompurify
Introduced in: 3.0.0Fixed in: 3.1.3
Fixnpm install dompurify@3.1.3

References