Executive brief
DOMPurify is a library used to clean HTML and prevent malicious scripts from running in web browsers. A flaw was found where the library fails to fully reset its security settings between different uses. This could allow a malicious actor to 'poison' the library's configuration, potentially leading to unauthorized script execution (XSS) in applications that reuse the same library instance for different tasks.
Technical details
A state contamination vulnerability exists in DOMPurify where the `trustedTypesPolicy` and `emptyHTML` internal variables are not reset by the `clearConfig()` function. The root cause is in `_parseConfig()`, which only initializes the internal policy if it is undefined, failing to overwrite or clear it when a new configuration is provided without a policy or with a null policy. If an application reuses a DOMPurify instance across trust boundaries, an attacker or a less-trusted component can install a malicious or weak Trusted Types policy. Subsequent calls requesting `RETURN_TRUSTED_TYPE` will then use the stale, potentially unsafe policy to sign the output, leading to XSS at Trusted Types sinks. This is fixed in version 3.4.9.
Affected products
- cure53 DOMPurify < 3.4.9
Timeline
- 2026-06-10: disclosed
- 2026-06-15: advisory
- 2026-06-15: patched: Fixed in version 3.4.9