Vulnerabilities/

DOMPurify has a SAFE_FOR_TEMPLATES bypass in RETURN_DOM mode

Severity:
Medium

Description

| Field | Value | |:——|:——| | Severity | Medium | | Affected | DOMPurify main at 883ac15, introduced in v1.0.10 (7fc196db) |

SAFE_FOR_TEMPLATES strips `` expressions from untrusted HTML.

Recommendation

Update the dompurify package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
dompurify
Anything's wrong? Let us know Last updated on April 27, 2026