File tree 5 files changed +120
-0
lines changed
5 files changed +120
-0
lines changed Original file line number Diff line number Diff line change 3177
3177
"bowername" : [" dompurify" , " DOMPurify" ],
3178
3178
"npmname" : " dompurify" ,
3179
3179
"vulnerabilities" : [
3180
+ {
3181
+ "ranges" : [
3182
+ {
3183
+ "atOrAbove" : " 0" ,
3184
+ "below" : " 3.2.4"
3185
+ }
3186
+ ],
3187
+ "summary" : " DOMPurify allows Cross-site Scripting (XSS)" ,
3188
+ "cwe" : [" CWE-79" ],
3189
+ "severity" : " medium" ,
3190
+ "identifiers" : {
3191
+ "CVE" : [" CVE-2025-26791" ],
3192
+ "githubID" : " GHSA-vhxf-7vqr-mrjg"
3193
+ },
3194
+ "info" : [
3195
+ " https://github.com/advisories/GHSA-vhxf-7vqr-mrjg" ,
3196
+ " https://nvd.nist.gov/vuln/detail/CVE-2025-26791" ,
3197
+ " https://github.com/cure53/DOMPurify/commit/d18ffcb554e0001748865da03ac75dd7829f0f02" ,
3198
+ " https://ensy.zip/posts/dompurify-323-bypass" ,
3199
+ " https://github.com/cure53/DOMPurify" ,
3200
+ " https://github.com/cure53/DOMPurify/releases/tag/3.2.4" ,
3201
+ " https://nsysean.github.io/posts/dompurify-323-bypass"
3202
+ ]
3203
+ },
3180
3204
{
3181
3205
"ranges" : [
3182
3206
{
Original file line number Diff line number Diff line change 4588
4588
" https://github.com/cure53/DOMPurify/commit/26e1d69ca7f769f5c558619d644d90dd8bf26ebc" ,
4589
4589
" https://github.com/cure53/DOMPurify"
4590
4590
]
4591
+ },
4592
+ {
4593
+ "atOrAbove" : " 0" ,
4594
+ "below" : " 3.2.4" ,
4595
+ "cwe" : [
4596
+ " CWE-79"
4597
+ ],
4598
+ "severity" : " medium" ,
4599
+ "identifiers" : {
4600
+ "summary" : " DOMPurify allows Cross-site Scripting (XSS)" ,
4601
+ "CVE" : [
4602
+ " CVE-2025-26791"
4603
+ ],
4604
+ "githubID" : " GHSA-vhxf-7vqr-mrjg"
4605
+ },
4606
+ "info" : [
4607
+ " https://github.com/advisories/GHSA-vhxf-7vqr-mrjg" ,
4608
+ " https://nvd.nist.gov/vuln/detail/CVE-2025-26791" ,
4609
+ " https://github.com/cure53/DOMPurify/commit/d18ffcb554e0001748865da03ac75dd7829f0f02" ,
4610
+ " https://ensy.zip/posts/dompurify-323-bypass" ,
4611
+ " https://github.com/cure53/DOMPurify" ,
4612
+ " https://github.com/cure53/DOMPurify/releases/tag/3.2.4" ,
4613
+ " https://nsysean.github.io/posts/dompurify-323-bypass"
4614
+ ]
4591
4615
}
4592
4616
],
4593
4617
"extractors" : {
Original file line number Diff line number Diff line change 4685
4685
" https://github.com/cure53/DOMPurify/commit/26e1d69ca7f769f5c558619d644d90dd8bf26ebc" ,
4686
4686
" https://github.com/cure53/DOMPurify"
4687
4687
]
4688
+ },
4689
+ {
4690
+ "atOrAbove" : " 0" ,
4691
+ "below" : " 3.2.4" ,
4692
+ "cwe" : [
4693
+ " CWE-79"
4694
+ ],
4695
+ "severity" : " medium" ,
4696
+ "identifiers" : {
4697
+ "summary" : " DOMPurify allows Cross-site Scripting (XSS)" ,
4698
+ "CVE" : [
4699
+ " CVE-2025-26791"
4700
+ ],
4701
+ "githubID" : " GHSA-vhxf-7vqr-mrjg"
4702
+ },
4703
+ "info" : [
4704
+ " https://github.com/advisories/GHSA-vhxf-7vqr-mrjg" ,
4705
+ " https://nvd.nist.gov/vuln/detail/CVE-2025-26791" ,
4706
+ " https://github.com/cure53/DOMPurify/commit/d18ffcb554e0001748865da03ac75dd7829f0f02" ,
4707
+ " https://ensy.zip/posts/dompurify-323-bypass" ,
4708
+ " https://github.com/cure53/DOMPurify" ,
4709
+ " https://github.com/cure53/DOMPurify/releases/tag/3.2.4" ,
4710
+ " https://nsysean.github.io/posts/dompurify-323-bypass"
4711
+ ]
4688
4712
}
4689
4713
],
4690
4714
"extractors" : {
Original file line number Diff line number Diff line change 4684
4684
" https://github.com/cure53/DOMPurify/commit/26e1d69ca7f769f5c558619d644d90dd8bf26ebc" ,
4685
4685
" https://github.com/cure53/DOMPurify"
4686
4686
]
4687
+ },
4688
+ {
4689
+ "atOrAbove" : " 0" ,
4690
+ "below" : " 3.2.4" ,
4691
+ "cwe" : [
4692
+ " CWE-79"
4693
+ ],
4694
+ "severity" : " medium" ,
4695
+ "identifiers" : {
4696
+ "summary" : " DOMPurify allows Cross-site Scripting (XSS)" ,
4697
+ "CVE" : [
4698
+ " CVE-2025-26791"
4699
+ ],
4700
+ "githubID" : " GHSA-vhxf-7vqr-mrjg"
4701
+ },
4702
+ "info" : [
4703
+ " https://github.com/advisories/GHSA-vhxf-7vqr-mrjg" ,
4704
+ " https://nvd.nist.gov/vuln/detail/CVE-2025-26791" ,
4705
+ " https://github.com/cure53/DOMPurify/commit/d18ffcb554e0001748865da03ac75dd7829f0f02" ,
4706
+ " https://ensy.zip/posts/dompurify-323-bypass" ,
4707
+ " https://github.com/cure53/DOMPurify" ,
4708
+ " https://github.com/cure53/DOMPurify/releases/tag/3.2.4" ,
4709
+ " https://nsysean.github.io/posts/dompurify-323-bypass"
4710
+ ]
4687
4711
}
4688
4712
],
4689
4713
"extractors" : {
Original file line number Diff line number Diff line change 4552
4552
" https://github.com/cure53/DOMPurify/commit/26e1d69ca7f769f5c558619d644d90dd8bf26ebc" ,
4553
4553
" https://github.com/cure53/DOMPurify"
4554
4554
]
4555
+ },
4556
+ {
4557
+ "atOrAbove" : " 0" ,
4558
+ "below" : " 3.2.4" ,
4559
+ "cwe" : [
4560
+ " CWE-79"
4561
+ ],
4562
+ "severity" : " medium" ,
4563
+ "identifiers" : {
4564
+ "summary" : " DOMPurify allows Cross-site Scripting (XSS)" ,
4565
+ "CVE" : [
4566
+ " CVE-2025-26791"
4567
+ ],
4568
+ "githubID" : " GHSA-vhxf-7vqr-mrjg"
4569
+ },
4570
+ "info" : [
4571
+ " https://github.com/advisories/GHSA-vhxf-7vqr-mrjg" ,
4572
+ " https://nvd.nist.gov/vuln/detail/CVE-2025-26791" ,
4573
+ " https://github.com/cure53/DOMPurify/commit/d18ffcb554e0001748865da03ac75dd7829f0f02" ,
4574
+ " https://ensy.zip/posts/dompurify-323-bypass" ,
4575
+ " https://github.com/cure53/DOMPurify" ,
4576
+ " https://github.com/cure53/DOMPurify/releases/tag/3.2.4" ,
4577
+ " https://nsysean.github.io/posts/dompurify-323-bypass"
4578
+ ]
4555
4579
}
4556
4580
],
4557
4581
"extractors" : {
You can’t perform that action at this time.
0 commit comments