Skip to content

Commit fddb044

Browse files
committed
Add missing DOMPurify vuln
1 parent 8bd058e commit fddb044

5 files changed

+120
-0
lines changed

repository/jsrepository-master.json

+24
Original file line numberDiff line numberDiff line change
@@ -3177,6 +3177,30 @@
31773177
"bowername": ["dompurify", "DOMPurify"],
31783178
"npmname": "dompurify",
31793179
"vulnerabilities": [
3180+
{
3181+
"ranges": [
3182+
{
3183+
"atOrAbove": "0",
3184+
"below": "3.2.4"
3185+
}
3186+
],
3187+
"summary": "DOMPurify allows Cross-site Scripting (XSS)",
3188+
"cwe": ["CWE-79"],
3189+
"severity": "medium",
3190+
"identifiers": {
3191+
"CVE": ["CVE-2025-26791"],
3192+
"githubID": "GHSA-vhxf-7vqr-mrjg"
3193+
},
3194+
"info": [
3195+
"https://github.com/advisories/GHSA-vhxf-7vqr-mrjg",
3196+
"https://nvd.nist.gov/vuln/detail/CVE-2025-26791",
3197+
"https://github.com/cure53/DOMPurify/commit/d18ffcb554e0001748865da03ac75dd7829f0f02",
3198+
"https://ensy.zip/posts/dompurify-323-bypass",
3199+
"https://github.com/cure53/DOMPurify",
3200+
"https://github.com/cure53/DOMPurify/releases/tag/3.2.4",
3201+
"https://nsysean.github.io/posts/dompurify-323-bypass"
3202+
]
3203+
},
31803204
{
31813205
"ranges": [
31823206
{

repository/jsrepository-v2.json

+24
Original file line numberDiff line numberDiff line change
@@ -4588,6 +4588,30 @@
45884588
"https://github.com/cure53/DOMPurify/commit/26e1d69ca7f769f5c558619d644d90dd8bf26ebc",
45894589
"https://github.com/cure53/DOMPurify"
45904590
]
4591+
},
4592+
{
4593+
"atOrAbove": "0",
4594+
"below": "3.2.4",
4595+
"cwe": [
4596+
"CWE-79"
4597+
],
4598+
"severity": "medium",
4599+
"identifiers": {
4600+
"summary": "DOMPurify allows Cross-site Scripting (XSS)",
4601+
"CVE": [
4602+
"CVE-2025-26791"
4603+
],
4604+
"githubID": "GHSA-vhxf-7vqr-mrjg"
4605+
},
4606+
"info": [
4607+
"https://github.com/advisories/GHSA-vhxf-7vqr-mrjg",
4608+
"https://nvd.nist.gov/vuln/detail/CVE-2025-26791",
4609+
"https://github.com/cure53/DOMPurify/commit/d18ffcb554e0001748865da03ac75dd7829f0f02",
4610+
"https://ensy.zip/posts/dompurify-323-bypass",
4611+
"https://github.com/cure53/DOMPurify",
4612+
"https://github.com/cure53/DOMPurify/releases/tag/3.2.4",
4613+
"https://nsysean.github.io/posts/dompurify-323-bypass"
4614+
]
45914615
}
45924616
],
45934617
"extractors": {

repository/jsrepository-v3.json

+24
Original file line numberDiff line numberDiff line change
@@ -4685,6 +4685,30 @@
46854685
"https://github.com/cure53/DOMPurify/commit/26e1d69ca7f769f5c558619d644d90dd8bf26ebc",
46864686
"https://github.com/cure53/DOMPurify"
46874687
]
4688+
},
4689+
{
4690+
"atOrAbove": "0",
4691+
"below": "3.2.4",
4692+
"cwe": [
4693+
"CWE-79"
4694+
],
4695+
"severity": "medium",
4696+
"identifiers": {
4697+
"summary": "DOMPurify allows Cross-site Scripting (XSS)",
4698+
"CVE": [
4699+
"CVE-2025-26791"
4700+
],
4701+
"githubID": "GHSA-vhxf-7vqr-mrjg"
4702+
},
4703+
"info": [
4704+
"https://github.com/advisories/GHSA-vhxf-7vqr-mrjg",
4705+
"https://nvd.nist.gov/vuln/detail/CVE-2025-26791",
4706+
"https://github.com/cure53/DOMPurify/commit/d18ffcb554e0001748865da03ac75dd7829f0f02",
4707+
"https://ensy.zip/posts/dompurify-323-bypass",
4708+
"https://github.com/cure53/DOMPurify",
4709+
"https://github.com/cure53/DOMPurify/releases/tag/3.2.4",
4710+
"https://nsysean.github.io/posts/dompurify-323-bypass"
4711+
]
46884712
}
46894713
],
46904714
"extractors": {

repository/jsrepository-v4.json

+24
Original file line numberDiff line numberDiff line change
@@ -4684,6 +4684,30 @@
46844684
"https://github.com/cure53/DOMPurify/commit/26e1d69ca7f769f5c558619d644d90dd8bf26ebc",
46854685
"https://github.com/cure53/DOMPurify"
46864686
]
4687+
},
4688+
{
4689+
"atOrAbove": "0",
4690+
"below": "3.2.4",
4691+
"cwe": [
4692+
"CWE-79"
4693+
],
4694+
"severity": "medium",
4695+
"identifiers": {
4696+
"summary": "DOMPurify allows Cross-site Scripting (XSS)",
4697+
"CVE": [
4698+
"CVE-2025-26791"
4699+
],
4700+
"githubID": "GHSA-vhxf-7vqr-mrjg"
4701+
},
4702+
"info": [
4703+
"https://github.com/advisories/GHSA-vhxf-7vqr-mrjg",
4704+
"https://nvd.nist.gov/vuln/detail/CVE-2025-26791",
4705+
"https://github.com/cure53/DOMPurify/commit/d18ffcb554e0001748865da03ac75dd7829f0f02",
4706+
"https://ensy.zip/posts/dompurify-323-bypass",
4707+
"https://github.com/cure53/DOMPurify",
4708+
"https://github.com/cure53/DOMPurify/releases/tag/3.2.4",
4709+
"https://nsysean.github.io/posts/dompurify-323-bypass"
4710+
]
46874711
}
46884712
],
46894713
"extractors": {

repository/jsrepository.json

+24
Original file line numberDiff line numberDiff line change
@@ -4552,6 +4552,30 @@
45524552
"https://github.com/cure53/DOMPurify/commit/26e1d69ca7f769f5c558619d644d90dd8bf26ebc",
45534553
"https://github.com/cure53/DOMPurify"
45544554
]
4555+
},
4556+
{
4557+
"atOrAbove": "0",
4558+
"below": "3.2.4",
4559+
"cwe": [
4560+
"CWE-79"
4561+
],
4562+
"severity": "medium",
4563+
"identifiers": {
4564+
"summary": "DOMPurify allows Cross-site Scripting (XSS)",
4565+
"CVE": [
4566+
"CVE-2025-26791"
4567+
],
4568+
"githubID": "GHSA-vhxf-7vqr-mrjg"
4569+
},
4570+
"info": [
4571+
"https://github.com/advisories/GHSA-vhxf-7vqr-mrjg",
4572+
"https://nvd.nist.gov/vuln/detail/CVE-2025-26791",
4573+
"https://github.com/cure53/DOMPurify/commit/d18ffcb554e0001748865da03ac75dd7829f0f02",
4574+
"https://ensy.zip/posts/dompurify-323-bypass",
4575+
"https://github.com/cure53/DOMPurify",
4576+
"https://github.com/cure53/DOMPurify/releases/tag/3.2.4",
4577+
"https://nsysean.github.io/posts/dompurify-323-bypass"
4578+
]
45554579
}
45564580
],
45574581
"extractors": {

0 commit comments

Comments
 (0)