CVE-2025-15599
published 2026-03-03CVE-2025-15599: DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by…
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.24%
15.8th percentile
DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting missing textarea rawtext element validation in the SAFE_FOR_XML regex. Attackers can include closing rawtext tags like in attribute values to break out of rawtext contexts and execute JavaScript when sanitized output is placed inside rawtext elements. The 3.x branch was fixed in 3.2.7; the 2.x branch was never patched.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cure53 | dompurify | 2.5.3 – 2.5.8 | — |
| cure53 | dompurify | 2.5.3 – 2.5.8 | — |
| cure53 | dompurify | >= 3.1.3 < 3.2.7 | 3.2.7 |
| cure53 | dompurify | >= 3.1.3 < 3.2.7 | 3.2.7 |
| cure53 | dompurify | 3.1.3 – 3.2.6 | — |
| debian | node-dompurify | < node-dompurify 3.3.2+dfsg-1 (forky) | node-dompurify 3.3.2+dfsg-1 (forky) |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv4.05.1MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv5.1MEDIUM
vendor_debian5.1MEDIUM
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
DOMPurify: DOMPurify: Cross-site scripting
vendor_redhat·2026-03-03·CVSS 5.1
CVE-2025-15599 [MEDIUM] CWE-79 DOMPurify: DOMPurify: Cross-site scripting
DOMPurify: DOMPurify: Cross-site scripting
DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting missing textarea rawtext element validation in the SAFE_FOR_XML regex. Attackers can include closing rawtext tags like in attribute values to break out of rawtext contexts and execute JavaScript when sanitized output is placed inside rawtext elements. The 3.x branch was fixed in 3.2.7; the 2.x branch was never patched.
A flaw was found in DOMPurify, a library designed to prevent web vulnerabilities. A remote attacker can exploit a cross-site scripting (XSS) vulnerability by bypassing the library's sanitization process. This bypass is possible due to improper validation of `textare
Debian
CVE-2025-15599: node-dompurify - DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scrip...
vendor_debian·2025·CVSS 5.1
CVE-2025-15599 [MEDIUM] CVE-2025-15599: node-dompurify - DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scrip...
DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting missing textarea rawtext element validation in the SAFE_FOR_XML regex. Attackers can include closing rawtext tags like in attribute values to break out of rawtext contexts and execute JavaScript when sanitized output is placed inside rawtext elements. The 3.x branch was fixed in 3.2.7; the 2.x branch was never patched.
Scope: local
bookworm: open
forky: resolved (fixed in 3.3.2+dfsg-1)
sid: resolved (fixed in 3.3.2+dfsg-1)
trixie: open
GHSA
DOMPurify contains a Cross-site Scripting vulnerability
ghsa·2026-03-03
CVE-2025-15599 [MEDIUM] CWE-79 DOMPurify contains a Cross-site Scripting vulnerability
DOMPurify contains a Cross-site Scripting vulnerability
DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting missing textarea rawtext element validation in the SAFE_FOR_XML regex. Attackers can include closing rawtext tags like in attribute values to break out of rawtext contexts and execute JavaScript when sanitized output is placed inside rawtext elements. The 3.x branch was fixed in 3.2.7; the 2.x branch was never patched.
OSV
CVE-2025-15599: DOMPurify 3
osv·2026-03-03·CVSS 5.1
CVE-2025-15599 [MEDIUM] CVE-2025-15599: DOMPurify 3
DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting missing textarea rawtext element validation in the SAFE_FOR_XML regex. Attackers can include closing rawtext tags like in attribute values to break out of rawtext contexts and execute JavaScript when sanitized output is placed inside rawtext elements. The 3.x branch was fixed in 3.2.7; the 2.x branch was never patched.
OSV
DOMPurify contains a Cross-site Scripting vulnerability
osv·2026-03-03
CVE-2025-15599 [MEDIUM] DOMPurify contains a Cross-site Scripting vulnerability
DOMPurify contains a Cross-site Scripting vulnerability
DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting missing textarea rawtext element validation in the SAFE_FOR_XML regex. Attackers can include closing rawtext tags like in attribute values to break out of rawtext contexts and execute JavaScript when sanitized output is placed inside rawtext elements. The 3.x branch was fixed in 3.2.7; the 2.x branch was never patched.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-15599 jupyterlab: DOMPurify: Cross-site scripting [fedora-all]
bugzilla·2026-03-03·CVSS 6.1
CVE-2025-15599 [MEDIUM] CVE-2025-15599 jupyterlab: DOMPurify: Cross-site scripting [fedora-all]
CVE-2025-15599 jupyterlab: DOMPurify: Cross-site scripting [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-15599 DOMPurify: DOMPurify: Cross-site scripting
bugzilla·2026-03-03·CVSS 6.1
CVE-2025-15599 [MEDIUM] CVE-2025-15599 DOMPurify: DOMPurify: Cross-site scripting
CVE-2025-15599 DOMPurify: DOMPurify: Cross-site scripting
DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting missing textarea rawtext element validation in the SAFE_FOR_XML regex. Attackers can include closing rawtext tags like in attribute values to break out of rawtext contexts and execute JavaScript when sanitized output is placed inside rawtext elements. The 3.x branch was fixed in 3.2.7; the 2.x branch was never patched.
Wiz
CVE-2025-15599 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.1
CVE-2025-15599 [MEDIUM] CVE-2025-15599 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-15599 :
JavaScript vulnerability analysis and mitigation
DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting missing textarea rawtext element validation in the SAFE_FOR_XML regex. Attackers can include closing rawtext tags like in attribute values to break out of rawtext contexts and execute JavaScript when sanitized output is placed inside rawtext elements. The 3.x branch was fixed in 3.2.7; the 2.x branch was never patched.
Source : NVD
## 5.1
Score
Published March 3, 2026
Severity MEDIUM
CNA Score 5.1
Affected Technologies
JavaScript
Grafana
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitat
2026-03-03
Published