Aller au contenu

Fiche vulnérabilité

CVE-2026-65913 : faille moyenne cure53 dompurify (CVSS 6.1)

Description

DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by polluting Array.prototype properties. Attackers can set Array.prototype properties like onclick to true, causing DOMPurify to accept event handlers as allowlisted attributes and resulting in DOM-based XSS when sanitized markup is rendered.

En bref

Sévérité
Moyenne (CVSS 6.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
23 juil. 2026
Dernière mise à jour
28 juil. 2026

Produits concernés

  • cure53 dompurify

Références

Rechercher une autre vulnérabilité dans la base CVE