CRITICAL 10.0 npm

DOMpurify has a nesting-based mXSS

GHSA-gx9m-whjm-85jf · CVE-2024-47875

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

DOMpurify was vulnerable to nesting-based mXSS

fixed by 0ef5e537 (2.x) and
merge 943

Backporter should be aware of GHSA-mmhx-hmjr-r674 (CVE-2024-45801) when cherry-picking

POC is avaible under test

Ready to move

Start Securing

Free, no credit card | First findings in minutes