Cure53 DOMPurify是Cure53公司开源的一款使用JavaScript编写的,用于HTML、MathML和SVG的DOM(文档对象模型)。 Cure53 DOMPurify 3.4.7之前版本存在跨站脚本漏洞,该漏洞源于IN_PLACE清理过程中可能跳过<template>.content内元素附加的阴影内容,导致攻击者控制的事件处理程序、JavaScript URL或脚本在应用程序克隆并插入已清理模板时存活并执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-47423 | 8.2 HIGH | DOMPurify XSS via `selectedcontent` re-clone |
| CVE-2026-49459 | 6.1 MEDIUM | DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS vi |
| CVE-2026-49458 | 6.1 MEDIUM | DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bou |
No comments yet