MODERATEnpm

DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS

DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS

CVE-2026-75838Published 2 weeks agoUpdated 1 week agoSource: OSV

Affected packages

  • dompurify

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS | HackTribune