{"id":"CVE-2026-65902","aliases":["GHSA-76mc-f452-cxcm"],"url":"https://o3.security/vulnerability/CVE-2026-65902","summary":"DOMPurify before 3.4.7 Hook Mutation Pollution via allowedTags","details":"DOMPurify before 3.4.7 (affected versions <= 3.4.5) passes direct references to the module-level DEFAULT_ALLOWED_TAGS and DEFAULT_ALLOWED_ATTR sets to the uponSanitizeElement and uponSanitizeAttribute hooks via data.allowedTags / data.allowedAttributes when sanitize is called without an explicit cfg.ALLOWED_TAGS / cfg.ALLOWED_ATTR array. A hook that mutates these fields permanently widens the default allow-lists for the lifetime of the DOMPurify instance, so all subsequent default-config sanitize calls inherit the widened defaults and attacker payloads using the poisoned tag/attribute name survive sanitization. removeAllHooks(), clearConfig(), and passing a fresh cfg do not recover the state; only constructing a new DOMPurify instance does.","published":"2026-07-23T13:16:20.528Z","modified":"2026-08-12T03:51:41.652844015Z","cvss":null,"epss":{"score":0.00237,"percentile":0.14741,"asOf":"2026-09-11"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"dompurify","fixedVersion":"3.4.7"}],"fix":{"url":"https://github.com/cure53/DOMPurify/commit/7996f1dc78eb8b7922388aed75d94a9f8fad9a36","label":"cure53/DOMPurify@7996f1d"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65902.json"},{"type":"ADVISORY","url":"https://github.com/cure53/DOMPurify/security/advisories/GHSA-76mc-f452-cxcm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-65902"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/dompurify-before-hook-mutation-pollution-via-allowedtags"},{"type":"FIX","url":"https://github.com/cure53/DOMPurify/commit/7996f1dc78eb8b7922388aed75d94a9f8fad9a36"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:41.652844015Z"}}