What is CVE-2026-65900?
DOMPurify versions 3.0.0 through 3.4.7, when using SAFE_FOR_TEMPLATES with DOM output modes, fail to sanitize template expressions (e.g., `${evil}`) inside `<template>` elements. This may lead to XSS attacks. Affected users should upgrade to version 3.4.8.
Azərbaycanca: DOMPurify 3.0.0-3.4.7 versiyalarında, SAFE_FOR_TEMPLATES DOM çıxış rejimi ilə konfiqurasiya edildikdə, `<template>` elementi daxilindəki template ifadələri (məsələn, `${evil}`) təmizlənmir. Bu, XSS hücumlarına yol aça bilər. Təsirə məruz qalan istifadəçilər 3.4.8 versiyasına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of DOMPurify are affected by CVE-2026-65900?
Versions 3.0.0 through 3.4.7 are affected.
How can I mitigate CVE-2026-65900?
You should upgrade DOMPurify to version 3.4.8.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.