Junglewise Threat Intelligence

CVE-2026-41239: DOMPurify has a SAFE_FOR_TEMPLATES bypass in RETURN_DOM mode

CVE-2026-41239 · Severity: medium · CVSS 6.8 · Published 2026-04-22

Technologies: Cure53 Dompurify. Vendors: npm.

Executive brief

DOMPurify is a widely-used HTML sanitizer that removes potentially malicious code from user-supplied content. When configured with SAFE_FOR_TEMPLATES and RETURN_DOM modes, it fails to strip template expressions (like {{...}}) from certain HTML structures, allowing attackers to inject XSS code that executes in template-evaluating frameworks like Vue 2. This can lead to arbitrary JavaScript execution and compromise of user sessions or data.

Technical details

DOMPurify has a two-pass sanitization strategy: per-node filtering during DOM traversal and a final string scrub after serialization. However, in RETURN_DOM and RETURN_DOM_FRAGMENT modes, the function returns early before the second pass runs. An attacker can exploit this by splitting template expression delimiters across multiple text nodes (e.g., { <disallowed-tag> } {payload} </disallowed-tag> }) so that no single node contains the complete {{ pattern; the per-node pass misses it. When DOMPurify removes the disallowed tags, adjacent text nodes merge, reconstituting the template expression. The resulting DOM is then mounted into a framework like Vue 2 which compiles and executes the injected code. The fix normalizes text nodes before returning in RETURN_DOM mode, ensuring the final string scrub catches reconstructed expressions.

Affected products

  • Cure53 DOMPurify <3.4.0

Timeline

  • 2026-04-22: disclosed
  • 2026-04-20: patched: Patched in version 3.4.0

References

Related threats