{"id":"CVE-2026-61784","summary":"xhtml-purifier has HTML attribute-injection (sanitizer bypass) that leads to XSS","details":"xhtml-purifier is a Node.js library to take in raw/unknown/untrusted HTML and output cleaned, purified, trusted HTML. Versions prior to 0.4.3 do not HTML-entity-encode attribute values when serializing its sanitized output. In attributeString() (XHTMLPurifier.js, around line 148) the attribute value is concatenated directly into a double-quoted attribute without encoding. As a result, an attacker-controlled value in any allowed attribute (class, style, title, alt, src, href) can include a double-quote character to break out of the attribute and inject an additional attribute, such as a JavaScript event handler (for example onmouseover or onerror). The injected handler survives sanitization and executes when the output is rendered, which is a sanitizer bypass leading to cross-site scripting. The fix in version 0.4.3 HTML-entity-encodes attribute values before serialization.","aliases":["GHSA-j8r4-32c5-33rc"],"modified":"2026-09-25T03:48:34.524131768Z","published":"2026-09-24T17:35:57.096Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-116","CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61784.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61784.json"},{"type":"FIX","url":"https://github.com/cstigler/node-xhtml-purifier/commit/21d461ad23e7bc9b3073693d5b51b9b8662044d3"},{"type":"ADVISORY","url":"https://github.com/cstigler/node-xhtml-purifier/security/advisories/GHSA-j8r4-32c5-33rc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61784"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cstigler/node-xhtml-purifier","events":[{"introduced":"0"},{"fixed":"8bc8f13a2ce95dc388122371846e491da361eb60"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.4.3"}],"source":"AFFECTED_FIELD"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-61784.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}