Dependency scanning
Check whether dompurify is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-75838
DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS
CVE-2026-66010
DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
CVE-2026-49459
DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM
CVE-2026-65898
DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)
CVE-2026-41238
DOMPurify: Prototype Pollution to XSS Bypass via CUSTOM_ELEMENT_HANDLING Fallback
CVE-2026-65914
DOMPurify is vulnerable to mutation-XSS via Re-Contextualization
CVE-2026-65901
DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects
CVE-2026-49978
DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content
CVE-2026-49458
DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks
CVE-2026-65900
DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes
CVE-2026-65902
DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`
CVE-2026-41240
DOMPurify: FORBID_TAGS bypassed by function-based ADD_TAGS predicate (asymmetry with FORBID_ATTR fix)
CVE-2026-41239
DOMPurify has a SAFE_FOR_TEMPLATES bypass in RETURN_DOM mode
CVE-2026-65912
DOMPurify ADD_ATTR predicate skips URI validation
CVE-2026-65913
DOMPurify USE_PROFILES prototype pollution allows event handlers
CVE-2026-65903
DOMPurify's ADD_TAGS function form bypasses FORBID_TAGS due to short-circuit evaluation
CVE-2025-15599
DOMPurify contains a Cross-site Scripting vulnerability
CVE-2026-0540
DOMPurify contains a Cross-site Scripting vulnerability
CVE-2024-47875
DOMpurify has a nesting-based mXSS
CVE-2024-45801
DOMPurify allows tampering by prototype pollution
CVE-2026-65899
DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output
CVE-2025-26791
DOMPurify allows Cross-site Scripting (XSS)
CVE-2026-47423
DOMPurify XSS via selectedcontent re-clone
CVE-2024-48910
DOMPurify vulnerable to tampering by prototype polution
CVE-2019-25155
DOMPurify Open Redirect vulnerability
CVE-2020-26870
Cross-site Scripting in dompurify
CVE-2019-16728
Cross-Site Scripting in dompurify
GHSA-mjjq-c88q-qhr6
Cross-Site Scripting in dompurify
Browse more npm advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes