DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees. Attackers can supply HTML with event handlers on descendant elements that execute after sanitization completes, even though the returned root appears clean.
Metrics
Affected Vendors & Products
References
History
Tue, 18 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees. Attackers can supply HTML with event handlers on descendant elements that execute after sanitization completes, even though the returned root appears clean. | |
| Title | DOMPurify before 3.4.13 Cross-Site Scripting via IN_PLACE hook | |
| First Time appeared |
Cure53
Cure53 dompurify |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cure53
Cure53 dompurify |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-18T13:38:34.515Z
Reserved: 2026-08-18T10:59:33.701Z
Link: CVE-2026-75838
No data.
Status : Received
Published: 2026-08-18T12:19:34.050
Modified: 2026-08-18T14:18:11.220
Link: CVE-2026-75838
No data.
OpenCVE Enrichment
Updated: 2026-08-18T15:00:05Z