CVE Explorer
CVE-2026-65914
DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wrappers like script, xmp, iframe, noembed, noframes, or noscript. Attackers can craft payloads with closing sequences that break out of the wrapper context during reparsing, reactivating dangerous markup with event handlers to execute JavaScript.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","packageURL":"pkg:npm/dompurify","product":"DOMPurify","vendor":"cure53","versions":[{"lessThan":"3.3.2","status":"affected","version":"0","versionType":"semver"},{"status":"unaffected","version":"3.3.2","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:173c5c9f167c73658d31ea266b5acbd14c26b29cfe5fd7c48c5270b095f75650 · sha256:bf0e6a6684aba3eb… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":5.3,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","userInteraction":"PASSIVE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:173c5c9f167c73658d31ea266b5acbd14c26b29cfe5fd7c48c5270b095f75650 · sha256:bf0e6a6684aba3eb… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-79","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:173c5c9f167c73658d31ea266b5acbd14c26b29cfe5fd7c48c5270b095f75650 · sha256:bf0e6a6684aba3eb… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"tags":["exploit"],"url":"https://github.com/cure53/DOMPurify/security/advisories/GHSA-h8r8-wccr-v5f2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:173c5c9f167c73658d31ea266b5acbd14c26b29cfe5fd7c48c5270b095f75650 · sha256:bf0e6a6684aba3eb… · /containers/adp/0/references/0
{"name":"GitHub Security Advisory (GHSA-h8r8-wccr-v5f2)","tags":["vendor-advisory"],"url":"https://github.com/cure53/DOMPurify/security/advisories/GHSA-h8r8-wccr-v5f2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:173c5c9f167c73658d31ea266b5acbd14c26b29cfe5fd7c48c5270b095f75650 · sha256:bf0e6a6684aba3eb… · /containers/cna/references/0
{"name":"VulnCheck Advisory: DOMPurify before 3.3.2 Mutation XSS via Re-Contextualization","tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/dompurify-before-mutation-xss-via-re-contextualization"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:173c5c9f167c73658d31ea266b5acbd14c26b29cfe5fd7c48c5270b095f75650 · sha256:bf0e6a6684aba3eb… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.