CVE-2026-65914
MEDIUMDOMPurify before 3.3.2 Mutation XSS via Re-Contextualization
Title source: cnaDescription
DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wrappers like script, xmp, iframe, noembed, noframes, or noscript. Attackers can craft payloads with closing sequences that break out of the wrapper context during reparsing, reactivating dangerous markup with event handlers to execute JavaScript.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-h8r8-wccr-v5f2)
https://github.com/cure53/DOMPurify/security/advisories/GHSA-h8r8-wccr-v5f2
Third Party Advisory third-party-advisory
VulnCheck Advisory: DOMPurify before 3.3.2 Mutation XSS via Re-Contextualization
https://www.vulncheck.com/advisories/dompurify-before-mutation-xss-via-re-contextualization
Scores
CVSS v3
6.1
EPSS
0.0017
EPSS Percentile
6.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (4)
cure53/DOMPurify
< 3.3.2
cure53/dompurify
< 3.3.2
cure53/DOMPurify
3.3.2
npm/dompurify
0 - 3.3.2npm
Published
Jul 23, 2026
Tracked Since
Jul 23, 2026