{"id":"CVE-2026-75838","aliases":["GHSA-55q2-fjhq-7xh7"],"url":"https://o3.security/vulnerability/CVE-2026-75838","summary":"DOMPurify before 3.4.13 Cross-Site Scripting via IN_PLACE hook","details":"DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detached subtrees. Attackers can supply HTML with event handlers on descendant elements that execute after sanitization completes, even though the returned root appears clean.","published":"2026-08-18T11:19:47.885Z","modified":"2026-08-20T03:54:45.984074749Z","cvss":null,"epss":{"score":0.003,"percentile":0.22183,"asOf":"2026-08-30"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"dompurify","fixedVersion":"3.4.13"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75838.json"},{"type":"ADVISORY","url":"https://github.com/cure53/DOMPurify/security/advisories/GHSA-55q2-fjhq-7xh7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75838"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/dompurify-before-cross-site-scripting-via-in-place-hook"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-20T03:54:45.984074749Z"}}