MEDIUM 6.1 npm

Cross-Site Scripting in dompurify

GHSA-chqj-j4fh-rw7m · CVE-2019-16728

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Versions of dompurify prior to 2.0.3 are vulnerable to Cross-Site Scripting (XSS). The package has an XSS filter bypass due to Mutation XSS in both Chrome and Safari through a combination of <svg>/<math> elements and </p>/</br>. An example payload is: <svg></p><style><a id="</style><img src=1 onerror=alert(1)>">. This allows attackers to bypass the XSS protection and execute arbitrary JavaScript in a victim's browser.

Recommendation

Upgrade to version 2.0.3 or later. You may also disallow <svg> and <math> through dompurify configurations:

     FORBID_TAGS: ['svg', 'math']
 });```

Ready to move

Start Securing

Free, no credit card | First findings in minutes