Executive brief
DOMPurify, a widely used security library for cleaning web content to prevent malicious scripts, contains a vulnerability in version 3.4.4. An attacker can bypass the security filters by using a specific HTML tag that causes the browser to re-load malicious code after the library has already finished its check. If exploited, this could allow an attacker to steal user data, hijack sessions, or perform unauthorized actions on behalf of users visiting a compromised website.
Technical details
A DOM-based cross-site scripting (XSS) vulnerability exists in DOMPurify version 3.4.4 due to the default inclusion of the 'selectedcontent' element in the allowed tags list. The vulnerability occurs because browsers may re-clone the content of a 'selectedcontent' element from its associated 'option' element after DOMPurify has already completed its sanitization pass. Specifically, if an attacker provides a payload where DOMPurify sanitizes the initial clone but then modifies the source 'option' element, the browser may refresh the 'selectedcontent' subtree with unsanitized markup that DOMPurify does not re-examine. This bypass is reproducible in Chromium and WebKit-based browsers. The issue is resolved in version 3.4.5 by removing 'selectedcontent' from the default allow-list.
Affected products
- cure53 DOMPurify 3.4.4
Timeline
- 2026-05-18: patched: Version 3.4.5 released
- 2026-05-19: advisory: GitHub Security Advisory published
- 2026-07-14: disclosed: CVE published to NVD