{"id":"GHSA-chqj-j4fh-rw7m","summary":"Cross-Site Scripting in dompurify","details":"Versions of `dompurify` prior to 2.0.3 are vulnerable to Cross-Site Scripting (XSS). The package has an XSS filter bypass due to Mutation XSS in both Chrome and Safari through a combination of `\u003csvg\u003e`/`\u003cmath\u003e` elements and `\u003c/p\u003e`/`\u003c/br\u003e`. An example payload is: `\u003csvg\u003e\u003c/p\u003e\u003cstyle\u003e\u003ca id=\"\u003c/style\u003e\u003cimg src=1 onerror=alert(1)\u003e\"\u003e`. This allows attackers to bypass the XSS protection and execute arbitrary JavaScript in a victim's browser.\n\n\n## Recommendation\n\nUpgrade to version 2.0.3 or later. You may also disallow `\u003csvg\u003e` and `\u003cmath\u003e` through `dompurify` configurations:\n```DOMPurify.sanitize(input, {\n     FORBID_TAGS: ['svg', 'math']\n });```","aliases":["CVE-2019-16728"],"modified":"2023-11-08T04:01:20.360896Z","published":"2020-08-28T21:25:11Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-08-28T21:24:05Z","nvd_published_at":null,"cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-16728"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2020/10/msg00029.html"},{"type":"WEB","url":"https://research.securitum.com/dompurify-bypass-using-mxss"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1205"}],"affected":[{"package":{"name":"dompurify","ecosystem":"npm","purl":"pkg:npm/dompurify"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.0.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/08/GHSA-chqj-j4fh-rw7m/GHSA-chqj-j4fh-rw7m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}