Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-crv5-9vww-q3g8 | DOMPurify has a SAFE_FOR_TEMPLATES bypass in RETURN_DOM mode |
Mon, 27 Apr 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cure53
Cure53 dompurify |
|
| Vendors & Products |
Cure53
Cure53 dompurify |
Sun, 26 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Sat, 25 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Apr 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TEMPLATES` strips `{{...}}` expressions from untrusted HTML. This works in string mode but not with `RETURN_DOM` or `RETURN_DOM_FRAGMENT`, allowing XSS via template-evaluating frameworks like Vue 2. Version 3.4.0 patches the issue. | |
| Title | DOMPurify has a SAFE_FOR_TEMPLATES bypass in RETURN_DOM mode | |
| Weaknesses | CWE-1289 CWE-79 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-25T01:21:43.094Z
Reserved: 2026-04-18T03:47:03.135Z
Link: CVE-2026-41239
Updated: 2026-04-25T01:21:38.842Z
Status : Deferred
Published: 2026-04-23T16:16:26.560
Modified: 2026-04-23T16:18:41.563
Link: CVE-2026-41239
OpenCVE Enrichment
Updated: 2026-04-28T07:45:26Z
Github GHSA