Executive brief
DOMPurify is a popular library used to clean and sanitize HTML to prevent security vulnerabilities like Cross-Site Scripting (XSS). A flaw in how the library manages its internal configuration allows security settings from one task to "leak" into subsequent tasks if the library instance is reused. This could allow an attacker to bypass security filters and execute malicious scripts in a user's browser, particularly in complex web applications that share a single sanitizer across different components.
Technical details
A state contamination vulnerability exists in DOMPurify versions 3.0.0 through 3.4.8 due to the 'clearConfig()' method failing to reset the internal 'trustedTypesPolicy' and 'emptyHTML' variables. When a DOMPurify instance is reused across different trust boundaries, a previously set 'TRUSTED_TYPES_POLICY' remains active even after a configuration reset. If a subsequent caller requests 'RETURN_TRUSTED_TYPE' output, they receive a 'TrustedHTML' object generated by the stale, potentially unsafe policy instead of a clean default. This can lead to Cross-Site Scripting (XSS) at a Trusted Types sink. The issue is fixed in version 3.4.9 by ensuring the Trusted Types state is properly cleared during configuration resets.
Affected products
- cure53 DOMPurify 3.0.0 to 3.4.8
Timeline
- 2026-06-10: advisory: GitHub Security Advisory GHSA-vxr8-fq34-vvx9 published
- 2026-07-23: disclosed: CVE-2026-65899 published to NVD
- 2026-07-23: patched: Fix identified in version 3.4.9