UNKNOWN npm
Cross-Site Scripting in dompurify
GHSA-mjjq-c88q-qhr6
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Versions of dompurify prior to 2.0.7 are vulnerable to Cross-Site Scripting (XSS). It is possible to bypass the package sanitization through Mutation XSS, which may allow an attacker to execute arbitrary JavaScript in a victim's browser.
Recommendation
Upgrade to version 2.0.7 or later.
Ready to move
Start Securing
Free, no credit card | First findings in minutes