VDB
Sign up
MEDIUM4.5

GHSA-vhxf-7vqr-mrjg

DOMPurify allows Cross-site Scripting (XSS)

Quick fix

GHSA-vhxf-7vqr-mrjg — dompurify: upgrade to the fixed version with the command below.

npm install dompurify@3.2.4

Details

DOMPurify before 3.2.4 has an incorrect template literal regular expression when SAFE_FOR_TEMPLATES is set to true, sometimes leading to mutation cross-site scripting (mXSS).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/dompurify
Introduced in: 0Fixed in: 3.2.4
Fixnpm install dompurify@3.2.4

References