QID 982802
QID 982802: Nodejs (npm) Security Update for dompurify (GHSA-63q7-h895-m982)
Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-63q7-h895-m982 for updates pertaining to this vulnerability.
Vendor References
- GHSA-63q7-h895-m982 -
github.com/advisories/GHSA-63q7-h895-m982
CVEs related to QID 982802
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-63q7-h895-m982 | dompurify |
|