Executive brief
DOMPurify, a library used to clean HTML and prevent malicious scripts from running in browsers, contains a flaw that can lead to Cross-Site Scripting (XSS). When the library is configured with a persistent policy and specific custom rules (hooks), a single 'trusted' piece of content can permanently corrupt the security settings for all subsequent content processed by that instance. This allows an attacker to bypass security filters and execute malicious code in the browsers of other users.
Technical details
A vulnerability exists in DOMPurify where the 'clone-guard' intended to prevent hook-based pollution of the global ALLOWED_ATTR object is bypassed when using the persistent configuration API setConfig(). When setConfig() is called, the library sets a internal flag that causes subsequent sanitize() calls to skip the _parseConfig() function where the protective cloning occurs. If an uponSanitizeAttribute hook is registered that mutates data.allowedAttributes, it modifies the live, shared allowlist object permanently for the lifetime of the DOMPurify instance. An attacker can exploit this by submitting content that triggers a conditional allowlist expansion (e.g., for a trusted element), which then persists and allows dangerous attributes like 'onerror' on all future untrusted content. This is an incomplete fix for a similar issue addressed in version 3.4.7.
Affected products
- cure53 dompurify <= 3.4.10
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory
- 2026-06-18: patched: Fixed in version 3.4.11