Cross-Site Scripting in dompurify
GHSA-chqj-j4fh-rw7m · CVE-2019-16728
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Versions of dompurify prior to 2.0.3 are vulnerable to Cross-Site Scripting (XSS). The package has an XSS filter bypass due to Mutation XSS in both Chrome and Safari through a combination of <svg>/<math> elements and </p>/</br>. An example payload is: <svg></p><style><a id="</style><img src=1 onerror=alert(1)>">. This allows attackers to bypass the XSS protection and execute arbitrary JavaScript in a victim's browser.
Recommendation
Upgrade to version 2.0.3 or later. You may also disallow <svg> and <math> through dompurify configurations:
FORBID_TAGS: ['svg', 'math']
});```
Ready to move
Start Securing
Free, no credit card | First findings in minutes