DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wrappers like script, xmp, iframe, noembed, noframes, or noscript. Attackers can craft payloads with closing sequences that break out of the wrapper context during reparsing, reactivating dangerous markup with event handlers to execute JavaScript.
References
| Link | Resource |
|---|---|
| https://github.com/cure53/DOMPurify/security/advisories/GHSA-h8r8-wccr-v5f2 | Exploit Third Party Advisory |
| https://www.vulncheck.com/advisories/dompurify-before-mutation-xss-via-re-contextualization | Third Party Advisory |
| https://github.com/cure53/DOMPurify/security/advisories/GHSA-h8r8-wccr-v5f2 | Exploit Third Party Advisory |
Configurations
History
28 Jul 2026, 15:49
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
| First Time |
Cure53 dompurify
Cure53 |
|
| References | () https://github.com/cure53/DOMPurify/security/advisories/GHSA-h8r8-wccr-v5f2 - Exploit, Third Party Advisory | |
| References | () https://www.vulncheck.com/advisories/dompurify-before-mutation-xss-via-re-contextualization - Third Party Advisory |
23 Jul 2026, 14:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-23 14:18
Updated : 2026-07-28 15:49
NVD link : CVE-2026-65914
Mitre link : CVE-2026-65914
CVE.ORG link : CVE-2026-65914
JSON object : View
Products Affected
cure53
- dompurify
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
