Junglewise Threat Intelligence

cure53 DOMPurify state contamination in Trusted Types policy

Severity: low · CVSS 2.1 · Published 2026-06-15

Technologies: dompurify (npm). Vendors: npm.

Executive brief

DOMPurify is a library used to clean HTML and prevent malicious scripts from running in web browsers. A flaw was found where the library fails to fully reset its security settings between different uses. This could allow a malicious actor to 'poison' the library's configuration, potentially leading to unauthorized script execution (XSS) in applications that reuse the same library instance for different tasks.

Technical details

A state contamination vulnerability exists in DOMPurify where the `trustedTypesPolicy` and `emptyHTML` internal variables are not reset by the `clearConfig()` function. The root cause is in `_parseConfig()`, which only initializes the internal policy if it is undefined, failing to overwrite or clear it when a new configuration is provided without a policy or with a null policy. If an application reuses a DOMPurify instance across trust boundaries, an attacker or a less-trusted component can install a malicious or weak Trusted Types policy. Subsequent calls requesting `RETURN_TRUSTED_TYPE` will then use the stale, potentially unsafe policy to sign the output, leading to XSS at Trusted Types sinks. This is fixed in version 3.4.9.

Affected products

  • cure53 DOMPurify < 3.4.9

Timeline

  • 2026-06-10: disclosed
  • 2026-06-15: advisory
  • 2026-06-15: patched: Fixed in version 3.4.9

References

Related threats