| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rp9w-3fw7-7cwq | DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 21 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Jul 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cure53
Cure53 dompurify |
|
| Vendors & Products |
Cure53
Cure53 dompurify |
Wed, 15 Jul 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Tue, 14 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow contents attached to an element inside <template>.content, allowing attacker-controlled markup such as event handlers, JavaScript URLs, or scripts to survive and execute when an application cloned and inserted the sanitized template. This issue is fixed in version 3.4.7. | |
| Title | DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-21T14:59:20.582Z
Reserved: 2026-06-02T18:30:51.281Z
Link: CVE-2026-49978
Updated: 2026-07-21T14:58:53.763Z
No data.
OpenCVE Enrichment
Updated: 2026-07-22T08:45:02Z
Github GHSA