#VU126317 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in DOMPurify
Published: April 16, 2026
DOMPurify
Cure53
Description
The vulnerability allows a remote attacker to execute arbitrary script in the browser.
The vulnerability exists due to improper input validation in URI validation for ADD_ATTR predicate handling when sanitizing input with a predicate-based attribute allowlist. A remote attacker can supply crafted HTML containing a javascript: URL to execute arbitrary script in the browser.
User interaction is required to activate the malicious link.