Vulnerabilities/

DOMPurify allows Cross-site Scripting (XSS)

Severity:
Medium

Description

DOMPurify before 3.2.4 has an incorrect template literal regular expression when SAFE_FOR_TEMPLATES is set to true, sometimes leading to mutation cross-site scripting (mXSS).

Recommendation

Update the dompurify package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
dompurify
Anything's wrong? Let us know Last updated on June 30, 2025

This issue is available in SmartScanner Professional

See Pricing