VDB
Sign up
CRITICAL

GHSA-mjjq-c88q-qhr6

Cross-Site Scripting in dompurify

Quick fix

GHSA-mjjq-c88q-qhr6 — dompurify: upgrade to the fixed version with the command below.

npm install dompurify@2.0.7

Details

Versions of `dompurify` prior to 2.0.7 are vulnerable to Cross-Site Scripting (XSS). It is possible to bypass the package sanitization through Mutation XSS, which may allow an attacker to execute arbitrary JavaScript in a victim's browser.

## Recommendation

Upgrade to version 2.0.7 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/dompurify
Introduced in: 0Fixed in: 2.0.7
Fixnpm install dompurify@2.0.7

References