Reflected cross-site scripting (XSS) In node-dompurify
Description
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside is returned. This issue is fixed in version 3.4.5.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 3.4.5 | ||
debian 13 | - | ||
debian 12 | - | ||
debian 14 | 3.4.5+dfsg-1 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2.