CVE-2026-0540

Severity CVSS v4.0:
MEDIUM
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
03/03/2026
Last modified:
25/03/2026

Description

DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 2726c74, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, noembed, noframes, iframe) in the SAFE_FOR_XML regex. Attackers can include payloads like in attribute values to execute JavaScript when sanitized output is placed inside these unprotected rawtext contexts.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:* 2.5.3 (including) 2.5.8 (including)
cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:* 3.1.3 (including) 3.3.1 (including)