You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Affected versions of this package are vulnerable to Template Injection in purify.js, due to inconsistencies in the parsing of XML and HTML tags. Executable code can be injected in HTML inside XML CDATA blocks.
Introduced through
[email protected]
Fixed in
[email protected], @3.0.11
Exploit maturity
PROOF OF CONCEPT
Detailed paths and remediation
Introduced through: [email protected] › [email protected]
Fix: Upgrade to [email protected]
Security information
Factors contributing to the scoring:
Snyk: CVSS 5.3 - Medium Severity
NVD: NVD only publishes analysis of vulnerabilities which are assigned a CVE ID. This vulnerability currently does not have an assigned CVE ID.
Why are the scores different? Learn how Snyk evaluates vulnerability scores
Overview
dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG.
Affected versions of this package are vulnerable to Template Injection in purify.js, due to inconsistencies in the parsing of XML and HTML tags. Executable code can be injected in HTML inside XML CDATA blocks.
Completion Criteria
The text was updated successfully, but these errors were encountered: