DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

GHSA-P98J-92PF-MC4P: GHSA-P98J-92PF-MC4P: DOM-Based Cross-Site Scripting (DOM XSS) via Hook Detach Bypass in DOMPurify In-Place Sanitization

GHSA-P98J-92PF-MC4P: DOM-Based Cross-Site Scripting (DOM XSS) via Hook Detach Bypass in DOMPurify In-Place Sanitization

Vulnerability ID: GHSA-P98J-92PF-MC4P
CVSS Score: 8.1
Published: 2026-09-30

A DOM-based Cross-Site Scripting (DOM XSS) vulnerability in DOMPurify allows attackers to bypass sanitization when using the in-place sanitization configuration (IN_PLACE: true) combined with custom hooks. If custom hooks detach elements during post-processing phases, nested malicious payloads can escape sterilization and execute in the browser's context.

TL;DR

DOMPurify versions prior to 3.4.16 are vulnerable to DOM XSS when using in-place sanitization with custom hooks. If a hook detaches an element during the afterSanitizeElements or afterSanitizeAttributes phases, nested payloads avoid sanitization and execute in the browser.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-79
  • Attack Vector: Network (Client-Side DOM XSS)
  • CVSS Score: 8.1 (High)
  • Exploit Status: Proof-of-Concept (PoC)
  • KEV Status: Not Listed
  • Impact: Arbitrary Client-Side Code Execution

Affected Systems

  • Applications utilizing DOMPurify (npm package: dompurify) with both custom lifecycle hooks and the in-place sanitization configuration (IN_PLACE: true).
  • dompurify: < 3.4.16 (Fixed in: 3.4.16)

Code Analysis

Commit: b9b9d80

Enforce detachment neutralization across all post-sanitization hook lifecycles and implement root-node fail-closed checks.

Exploit Details

  • GitHub: A fully reproducible proof-of-concept exists within the library's official test suite.

Mitigation Strategies

  • Upgrade DOMPurify to version 3.4.16 or higher
  • Avoid programmatic node detachment inside custom hooks
  • Use native declarative configurations such as FORBID_TAGS instead of element removal hooks
  • Limit usage of IN_PLACE: true to performance-critical zones

Remediation Steps:

  1. Audit codebase for DOMPurify.sanitize calls utilizing the IN_PLACE configuration option
  2. Verify whether custom hooks are registered using afterSanitizeElements or afterSanitizeAttributes
  3. Update package.json dependencies to reference dompurify version 3.4.16 or higher
  4. Deploy updated client bundles to production environments

References


Read the full report for GHSA-P98J-92PF-MC4P on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)