Reflected cross-site scripting (XSS) In dompurify
Description
DOMPurify allows Cross-site Scripting (XSS) DOMPurify before 3.2.4 has an incorrect template literal regular expression when SAFE_FOR_TEMPLATES is set to true, sometimes leading to mutation cross-site scripting (mXSS).
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
npm | 3.2.4 | ||
debian 12 | - | ||
debian 13 | 3.1.7+dfsg+~3.0.5-2 | ||
debian 14 | 3.1.7+dfsg+~3.0.5-2 | ||
rpm rhel10 | - | - | |
rpm rhel8 | - | - | |
rpm rhel9 | - | - |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4.