CVE-2026-65913

DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by polluting Array.prototype properties. Attackers can set Array.prototype properties like onclick to true, causing DOMPurify to accept event handlers as allowlisted attributes and resulting in DOM-based XSS when sanitized markup is rendered.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:*

History

28 Jul 2026, 15:50

Type Values Removed Values Added
CPE cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:*
First Time Cure53 dompurify
Cure53
References () https://github.com/cure53/DOMPurify/security/advisories/GHSA-cj63-jhhr-wcxv - () https://github.com/cure53/DOMPurify/security/advisories/GHSA-cj63-jhhr-wcxv - Third Party Advisory
References () https://www.vulncheck.com/advisories/dompurify-before-prototype-pollution-via-use-profiles - () https://www.vulncheck.com/advisories/dompurify-before-prototype-pollution-via-use-profiles - Third Party Advisory

23 Jul 2026, 14:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-23 14:18

Updated : 2026-07-28 15:50


NVD link : CVE-2026-65913

Mitre link : CVE-2026-65913

CVE.ORG link : CVE-2026-65913


JSON object : View

Products Affected

cure53

  • dompurify
CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')