CVE-2025-26791

DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).

Open
LOW (1.8)

Add a comment

Mark as False Positive
Last calculated at:

Affected component

dompurify

Installed version:
3.1.6
Fixed in:
3.2.4

Quick Fix

Update all Dependencies
Update only dompurify

Management decisions across the organization

Copyright © 2025 L3montree GmbH and the DevGuard Contributors. All rights reserved. Version 2ab7b793efd72421aea8c3a994ac60202bf1b3a5