MEDIUM 5.1 NVD
CVE-2026-75838
DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees.
DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees. Attackers can supply HTML with event handlers on descendant elements that execute after sanitization completes, even though the returned root appears clean.
References
- https://github.com/cure53/DOMPurify/security/advisories/GHSA-55q2-fjhq-7xh7
- https://www.vulncheck.com/advisories/dompurify-before-cross-site-scripting-via-in-place-ho
This medium severity vulnerability with a CVSS score of 5.1 was published on 2026-08-18 via NVD.
vulnfeed aggregates 11001 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.