A AegiFlow
MEDIUMCVSS 5.1EPSS 0.2%

CVE-2026-65901

CVE-2026-65901 updated by NVD

Published
2026-06-15
Modified
2026-07-30
EPSS percentile
5%
Sources
github-advisory, nvd

Summary

DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled nodeName on live non-form nodes. Attackers can supply hostile live DOM objects with real script children whose observable nodeName is clobbered to appear as allowed elements, causing scripts to execute when the sanitized tree is inserted into a live document.

Affected packages

EcosystemPackageAffected versionsFixed versions
npmdompurify

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.