{"id":"GHSA-j8r4-32c5-33rc","summary":"xhtml-purifier has HTML attribute-injection (sanitizer bypass) that leads to XSS","details":"xhtml-purifier does not HTML-entity-encode attribute values when serializing its sanitized output. In attributeString() (XHTMLPurifier.js, around line 148) the attribute value is concatenated directly into a double-quoted attribute without encoding. As a result, an attacker-controlled value in any allowed attribute (class, style, title, alt, src, href) can include a double-quote character to break out of the attribute and inject an additional attribute, such as a JavaScript event handler (for example onmouseover or onerror). The injected handler survives sanitization and executes when the output is rendered, which is a sanitizer bypass leading to cross-site scripting. The fix HTML-entity-encodes attribute values before serialization.","aliases":["CVE-2026-61784"],"modified":"2026-09-24T19:45:04.825205046Z","published":"2026-09-24T19:33:23Z","database_specific":{"nvd_published_at":"2026-09-24T18:17:16Z","cwe_ids":["CWE-116","CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-09-24T19:33:23Z"},"references":[{"type":"WEB","url":"https://github.com/cstigler/node-xhtml-purifier/security/advisories/GHSA-j8r4-32c5-33rc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61784"},{"type":"WEB","url":"https://github.com/cstigler/node-xhtml-purifier/pull/6"},{"type":"WEB","url":"https://github.com/cstigler/node-xhtml-purifier/commit/21d461ad23e7bc9b3073693d5b51b9b8662044d3"},{"type":"PACKAGE","url":"https://github.com/cstigler/node-xhtml-purifier"},{"type":"WEB","url":"https://github.com/cstigler/node-xhtml-purifier/releases/tag/v0.4.3"}],"affected":[{"package":{"name":"xhtml-purifier","ecosystem":"npm","purl":"pkg:npm/xhtml-purifier"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.4.3"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.4.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-j8r4-32c5-33rc/GHSA-j8r4-32c5-33rc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}