Feed/CVE-2026-0540
CVE-2026-0540CVSS 6.1

CVE-2026-0540

Published Mar 3, 2026·Updated Jun 17, 2026

NVD Description

DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 2726c74, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, noembed, noframes, iframe) in the SAFE_FOR_XML regex. Attackers can include payloads like </noscript><img src=x onerror=alert(1)> in attribute values to execute JavaScript when sanitized output is placed inside these unprotected rawtext contexts.

Affected Packages (2)

dompurifyNPM
From 3.1.3
Fixed in 3.3.2
dompurifyNPM
From 2.5.3
Fixed in 2.5.9

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free