A AegiFlow
MEDIUMCVSS 5.3EPSS 0.2%

CVE-2026-65903

CVE-2026-65903 updated by NVD

Published
2026-04-16
Modified
2026-07-30
EPSS percentile
8%
Sources
github-advisory, nvd

Summary

DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluation allows forbidden tags to bypass FORBID_TAGS restrictions. Attackers can craft input containing tags listed in FORBID_TAGS that are also added via ADD_TAGS function, causing them to be retained in sanitized output.

Affected packages

EcosystemPackageAffected versionsFixed versions
npmdompurify3.4.0

Remediation: Upgrade to 3.4.0 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.