CVE-2026-0540 is a cross-site scripting (XSS) vulnerability affecting DOMPurify versions 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8. It allows attackers to bypass attribute sanitization by exploiting missing rawtext elements in the SAFE_FOR_XML regex, enabling injection of malicious JavaScript. This vulnerability has a CVSS score of 6.1 (MEDIUM), indicating a network-based attack with low complexity, requiring user interaction, and potentially leading to limited confidentiality and integrity impacts. The EPSS score is very low, suggesting a low probability of exploitation. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, with only one mention and one article, respectively.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.5.3, <= 2.5.8CPE match | cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:* | ||
>= 3.1.3, <= 3.3.1CPE match | cpe:2.3:a:cure53:dompurify:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.