CVE-2026-65914

MEDIUM

DOMPurify before 3.3.2 Mutation XSS via Re-Contextualization

Title source: cna
STIX 2.1

Description

DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wrappers like script, xmp, iframe, noembed, noframes, or noscript. Attackers can craft payloads with closing sequences that break out of the wrapper context during reparsing, reactivating dangerous markup with event handlers to execute JavaScript.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-h8r8-wccr-v5f2)
https://github.com/cure53/DOMPurify/security/advisories/GHSA-h8r8-wccr-v5f2
Third Party Advisory third-party-advisory
VulnCheck Advisory: DOMPurify before 3.3.2 Mutation XSS via Re-Contextualization
https://www.vulncheck.com/advisories/dompurify-before-mutation-xss-via-re-contextualization

Scores

CVSS v3 6.1
EPSS 0.0017
EPSS Percentile 6.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (4)
cure53/DOMPurify < 3.3.2
cure53/dompurify < 3.3.2
cure53/DOMPurify 3.3.2
npm/dompurify 0 - 3.3.2npm
Published Jul 23, 2026
Tracked Since Jul 23, 2026