What is CVE-2026-65913?
CVE-2026-65913 is a prototype pollution vulnerability in DOMPurify prior to version 3.3.2, primarily affecting the USE_PROFILES mode. Attackers can bypass attribute filtering by polluting Array.prototype properties, allowing malicious event handlers to be accepted. Affected users should immediately upgrade to DOMPurify version 3.3.2 or later.
Azərbaycanca: CVE-2026-65913, DOMPurify kitabxanasının 3.3.2-dən əvvəlki versiyalarında aşkarlanmış prototype pollution zəifliyidir. Bu zəiflik, xüsusilə USE_PROFILES rejimində Array.prototype xüsusiyyətlərini manipulyasiya edərək filtrdən yayınmağa imkan verir. Təsirə məruz qalan sistemlərdə təcili olaraq DOMPurify 3.3.2 və ya daha yuxarı versiyaya yeniləmə aparılmalıdır.
Related CVEs
link basis: same weakness class CWE-94
FAQ1
What library does CVE-2026-65913 affect and how is the vulnerability exploited?
CVE-2026-65913 affects the DOMPurify library in versions prior to 3.3.2. It is a prototype pollution vulnerability that, particularly in USE_PROFILES mode, allows attackers to bypass attribute filtering by polluting Array.prototype properties, enabling malicious event handlers to be accepted.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.