CVE-2025-26791
Moderate
CVE-2025-26791
DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).
Exploit probability
0.6%
Published
February 14, 2025
Required by
Not available
Last source change
August 12, 2026
02 / AFFECTED SOFTWARE
Affected packages
110 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2025-26791
View original source
DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).
Open Source Vulnerabilities
GHSA-vhxf-7vqr-mrjg
View original source
DOMPurify before 3.2.4 has an incorrect template literal regular expression when SAFE_FOR_TEMPLATES is set to true, sometimes leading to mutation cross-site scripting (mXSS).
05 / REFERENCES
Further evidence
- https://ensy.zip/posts/dompurify-323-bypass/
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/26xxx/CVE-2025-26791.json
- https://github.com/cure53/DOMPurify/commit/d18ffcb554e0001748865da03ac75dd7829f0f02
- https://github.com/cure53/DOMPurify/releases/tag/3.2.4
- https://nsysean.github.io/posts/dompurify-323-bypass/
- https://nvd.nist.gov/vuln/detail/CVE-2025-26791
- https://ensy.zip/posts/dompurify-323-bypass
- https://github.com/cure53/DOMPurify
- https://nsysean.github.io/posts/dompurify-323-bypass