Executive brief
DOMPurify is a widely-used JavaScript library that sanitizes HTML to prevent malicious script injection attacks. A vulnerability allows attackers to bypass DOMPurify's depth checking mechanism through prototype pollution, enabling them to inject and execute malicious scripts (XSS) that would normally be blocked. This could allow attackers to steal user credentials, deface web pages, or redirect users to malicious sites.
Technical details
DOMPurify fails to properly validate depth checking when processing nested HTML elements. Attackers can exploit this via prototype pollution (CWE-1321)—modifying JavaScript object prototypes to weaken the depth check enforcement. By crafting specially nested malicious HTML, an attacker can bypass sanitization and inject JavaScript that executes in the browser. No authentication or user interaction is required; exploitation requires network-reachable delivery of the malicious HTML to a page using a vulnerable version of DOMPurify. Patches are available in versions 2.5.4 and 3.1.3.
Affected products
- DOMPurify DOMPurify <2.5.4, 3.0.0 to <3.1.3
Timeline
- 2024-09-16: disclosed
- 2024-09-16: patched: Fixed in versions 2.5.4 and 3.1.3