GHSA-P98J-92PF-MC4P: DOM-Based Cross-Site Scripting (DOM XSS) via Hook Detach Bypass in DOMPurify In-Place Sanitization
Vulnerability ID: GHSA-P98J-92PF-MC4P
CVSS Score: 8.1
Published: 2026-09-30
A DOM-based Cross-Site Scripting (DOM XSS) vulnerability in DOMPurify allows attackers to bypass sanitization when using the in-place sanitization configuration (IN_PLACE: true) combined with custom hooks. If custom hooks detach elements during post-processing phases, nested malicious payloads can escape sterilization and execute in the browser's context.
TL;DR
DOMPurify versions prior to 3.4.16 are vulnerable to DOM XSS when using in-place sanitization with custom hooks. If a hook detaches an element during the afterSanitizeElements or afterSanitizeAttributes phases, nested payloads avoid sanitization and execute in the browser.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-79
- Attack Vector: Network (Client-Side DOM XSS)
- CVSS Score: 8.1 (High)
- Exploit Status: Proof-of-Concept (PoC)
- KEV Status: Not Listed
- Impact: Arbitrary Client-Side Code Execution
Affected Systems
- Applications utilizing DOMPurify (npm package: dompurify) with both custom lifecycle hooks and the in-place sanitization configuration (IN_PLACE: true).
-
dompurify: < 3.4.16 (Fixed in:
3.4.16)
Code Analysis
Commit: b9b9d80
Enforce detachment neutralization across all post-sanitization hook lifecycles and implement root-node fail-closed checks.
Exploit Details
- GitHub: A fully reproducible proof-of-concept exists within the library's official test suite.
Mitigation Strategies
- Upgrade DOMPurify to version 3.4.16 or higher
- Avoid programmatic node detachment inside custom hooks
- Use native declarative configurations such as FORBID_TAGS instead of element removal hooks
- Limit usage of IN_PLACE: true to performance-critical zones
Remediation Steps:
- Audit codebase for DOMPurify.sanitize calls utilizing the IN_PLACE configuration option
- Verify whether custom hooks are registered using afterSanitizeElements or afterSanitizeAttributes
- Update package.json dependencies to reference dompurify version 3.4.16 or higher
- Deploy updated client bundles to production environments
References
Read the full report for GHSA-P98J-92PF-MC4P on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)