A AegiFlow
MEDIUMCVSS 5.1EPSS 0.2%

CVE-2026-65898

CVE-2026-65898 updated by NVD

Published
2026-06-18
Modified
2026-07-30
EPSS percentile
5%
Sources
github-advisory, nvd

Summary

DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to permanently mutate the shared allowlist. Attackers can register a hook that conditionally allows dangerous attributes like onerror for trusted elements, then submit untrusted content that inherits the polluted allowlist and executes event handlers as stored XSS.

Affected packages

EcosystemPackageAffected versionsFixed versions
npmdompurify3.4.11

Remediation: Upgrade to 3.4.11 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.