CVE-2025-26791
published 2025-02-14CVE-2025-26791: DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).
PriorityP424medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.58%
44.4th percentile
DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cure53 | dompurify | < 3.2.4 | 3.2.4 |
| cure53 | dompurify | >= 0 < 3.2.4 | 3.2.4 |
| debian | node-dompurify | < node-dompurify 3.1.7+dfsg+~3.0.5-2 (forky) | node-dompurify 3.1.7+dfsg+~3.0.5-2 (forky) |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM
vendor_debian4.5MEDIUM
vendor_oracle4.5MEDIUM
vendor_redhat4.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Team Member (DOMPurify) — CVE-2025-26791
vendor_oracle·2026-01-15·CVSS 3.9
CVE-2025-26791 [MEDIUM] Oracle Oracle Construction and Engineering Risk Matrix: Team Member (DOMPurify) — CVE-2025-26791
Oracle Oracle Construction and Engineering Risk Matrix: Team Member (DOMPurify) vulnerability
CVE: CVE-2025-26791
CVSS: 3.9
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2026 (JAN 2026)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (DOMPurify) — CVE-2025-26791
vendor_oracle·2025-07-15·CVSS 4.5
CVE-2025-26791 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Core (DOMPurify) — CVE-2025-26791
Oracle Oracle Communications Applications Risk Matrix: Core (DOMPurify) vulnerability
CVE: CVE-2025-26791
CVSS: 4.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2025 (JUL 2025)
Red Hat
dompurify: Mutation XSS in DOMPurify Due to Improper Template Literal Handling
vendor_redhat·2025-02-14·CVSS 4.5
CVE-2025-26791 [MEDIUM] CWE-79 dompurify: Mutation XSS in DOMPurify Due to Improper Template Literal Handling
dompurify: Mutation XSS in DOMPurify Due to Improper Template Literal Handling
DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).
A flaw was found in DOMPurify. This vulnerability allows attackers to execute mutation-based Cross-site scripting (mXSS) via an incorrect template literal regular expression.
Package: cryostat/cryostat-rhel9 (Cryostat 3) - Fix deferred
Package: migration-toolkit-virtualization/mtv-console-plugin-rhel9 (Migration Toolkit for Virtualization) - Fix deferred
Package: kn-backstage-plugins-eventmesh-rhel8 (OpenShift Serverless) - Affected
Package: rhacm2/console-rhel8 (Red Hat Advanced Cluster Management for Kubernetes 2) - Fix deferred
Package: advanced-cluster-security/rhacs-
Debian
CVE-2025-26791: node-dompurify - DOMPurify before 3.2.4 has an incorrect template literal regular expression, som...
vendor_debian·2025·CVSS 4.5
CVE-2025-26791 [MEDIUM] CVE-2025-26791: node-dompurify - DOMPurify before 3.2.4 has an incorrect template literal regular expression, som...
DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).
Scope: local
bookworm: open
forky: resolved (fixed in 3.1.7+dfsg+~3.0.5-2)
sid: resolved (fixed in 3.1.7+dfsg+~3.0.5-2)
trixie: resolved (fixed in 3.1.7+dfsg+~3.0.5-2)
OSV
CVE-2025-26791: DOMPurify before 3
osv·2025-02-14·CVSS 6.1
CVE-2025-26791 [MEDIUM] CVE-2025-26791: DOMPurify before 3
DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).
GHSA
DOMPurify allows Cross-site Scripting (XSS)
ghsa·2025-02-14
CVE-2025-26791 [MEDIUM] CWE-79 DOMPurify allows Cross-site Scripting (XSS)
DOMPurify allows Cross-site Scripting (XSS)
DOMPurify before 3.2.4 has an incorrect template literal regular expression when SAFE_FOR_TEMPLATES is set to true, sometimes leading to mutation cross-site scripting (mXSS).
OSV
DOMPurify allows Cross-site Scripting (XSS)
osv·2025-02-14
CVE-2025-26791 [MEDIUM] DOMPurify allows Cross-site Scripting (XSS)
DOMPurify allows Cross-site Scripting (XSS)
DOMPurify before 3.2.4 has an incorrect template literal regular expression when SAFE_FOR_TEMPLATES is set to true, sometimes leading to mutation cross-site scripting (mXSS).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-02-14
Published