What is CVE-2026-65914?
CVE-2026-65914 is a mutation-XSS vulnerability in DOMPurify versions below 3.3.2, occurring when sanitized HTML is reinserted into special parsing contexts using innerHTML with wrappers like script or iframe. Attackers can exploit this by crafting payloads with closing sequences to break out of the wrapper context. Users should immediately upgrade to DOMPurify version 3.3.2 or later.
Azərbaycanca: CVE-2026-65914, DOMPurify kitabxanasının 3.3.2 versiyasından əvvəlki versiyalarında, təmizlənmiş HTML-in müəyyən parsing kontekstlərinə (məsələn, script, iframe kimi wrapper elementləri daxilində) təkrar daxil edilməsi zamanı yaranan mutation-XSS zəifliyidir. Təcavüzkarlar bu zəiflikdən istifadə edərək wrapper kontekstini qıraraq zərərli kod yeridə bilərlər. İstifadəçilər dərhal DOMPurify-i 3.3.2 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
Which versions of DOMPurify are affected by CVE-2026-65914?
All versions of DOMPurify below 3.3.2 are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.