CVE-2026-65913

DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by polluting Array.prototype properties. Attackers can set Array.prototype properties like onclick to true, causing DOMPurify to accept event handlers as allowlisted attributes and resulting in DOM-based XSS when sanitized markup is rendered.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-23 14:18

Updated : 2026-07-28 15:50


NVD link : CVE-2026-65913

Mitre link : CVE-2026-65913

CVE.ORG link : CVE-2026-65913


JSON object : View

Products Affected

cure53

  • dompurify
CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')