Back to overview

CVE-2026-65913

MEDIUM
6.1
CVSS 3.1
Description
DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by polluting Array.prototype properties. Attackers can set Array.prototype properties like onclick to true, causing DOMPurify to accept event handlers as allowlisted attributes and resulting in DOM-based XSS when sanitized markup is rendered.

Metadata

CVE ID
CVE-2026-65913
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-07-23 12:51 UTC
Published
2026-07-23 13:16 UTC
Last updated
2026-07-23 13:38 UTC
Primary CWE
CWE-1321
Improperly Controlled Modification of Object Prototype Attri…
Vendor / Product
cure53 / DOMPurify
Sources
cve.org  ·  NVD

Severity & Metrics

6.1 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
cure53 DOMPurify 0 < 3.3.2, 3.3.2
Weakness (CWE)
CWESourceDescription
CWE-1321 cna Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVSS scores (2)
ScoreSeverityVersionSourceVector
6.1 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
5.1 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
References (2)
Back to overview