VDB
Sign up
CRITICAL9.1

GHSA-p3vf-v8qc-cwcr

DOMPurify vulnerable to tampering by prototype polution

Quick fix

GHSA-p3vf-v8qc-cwcr — dompurify: upgrade to the fixed version with the command below.

npm install dompurify@2.4.2

Details

dompurify was vulnerable to prototype pollution

Fixed by https://github.com/cure53/DOMPurify/commit/d1dd0374caef2b4c56c3bd09fe1988c3479166dc

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/dompurify
Introduced in: 0Fixed in: 2.4.2
Fixnpm install dompurify@2.4.2

References