Search CVE reports
381 – 390 of 41070 results
DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by polluting Array.prototype properties. Attackers can set Array.prototype properties...
1 affected package
node-dompurify
| Package | 24.04 LTS |
|---|---|
| node-dompurify | Needs evaluation |
DOMPurify before 3.3.2 contains a URI validation bypass vulnerability when ADD_ATTR is provided as a predicate function via EXTRA_ELEMENT_HANDLING.attributeCheck. Attackers can supply a predicate that accepts specific attribute...
1 affected package
node-dompurify
| Package | 24.04 LTS |
|---|---|
| node-dompurify | Needs evaluation |
In DOMPurify through 3.3.3, function predicates supplied via ADD_ATTR or ADD_TAGS to DOMPurify.sanitize() persist in internal state (EXTRA_ELEMENT_HANDLING) across subsequent sanitize() calls on the same instance. If a later call...
1 affected package
node-dompurify
| Package | 24.04 LTS |
|---|---|
| node-dompurify | Needs evaluation |
DOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_PLACE mode when the element originates from a different window/realm (e.g., an iframe's contentDocument). A cross-realm instanceof check in the private _isNode()...
1 affected package
node-dompurify
| Package | 24.04 LTS |
|---|---|
| node-dompurify | Needs evaluation |
DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluation allows forbidden tags to bypass FORBID_TAGS restrictions. Attackers can craft input containing tags listed in FORBID_TAGS that...
1 affected package
node-dompurify
| Package | 24.04 LTS |
|---|---|
| node-dompurify | Needs evaluation |
DOMPurify before 3.4.7 (affected versions <= 3.4.5) passes direct references to the module-level DEFAULT_ALLOWED_TAGS and DEFAULT_ALLOWED_ATTR sets to the uponSanitizeElement and uponSanitizeAttribute hooks via data.allowedTags /...
1 affected package
node-dompurify
| Package | 24.04 LTS |
|---|---|
| node-dompurify | Needs evaluation |
DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled nodeName on live non-form nodes. Attackers can supply hostile live DOM objects with real script children whose...
1 affected package
node-dompurify
| Package | 24.04 LTS |
|---|---|
| node-dompurify | Needs evaluation |
DOMPurify versions >=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a DOM output mode (RETURN_DOM, RETURN_DOM_FRAGMENT, or IN_PLACE), fail to strip template expressions (e.g. ${evil}, {{evil}},...
1 affected package
node-dompurify
| Package | 24.04 LTS |
|---|---|
| node-dompurify | Needs evaluation |
DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is called, so a DOMPurify instance reused across trust boundaries stays bound to a previously supplied TRUSTED_TYPES_POLICY. A later...
1 affected package
node-dompurify
| Package | 24.04 LTS |
|---|---|
| node-dompurify | Needs evaluation |
DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to permanently mutate the shared allowlist. Attackers can register a hook that...
1 affected package
node-dompurify
| Package | 24.04 LTS |
|---|---|
| node-dompurify | Needs evaluation |