DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).
Metrics
Affected Vendors & Products
References
History
Wed, 12 Mar 2025 07:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat ansible Automation Platform
|
|
CPEs | cpe:/a:redhat:ansible_automation_platform:2.5::el8 cpe:/a:redhat:ansible_automation_platform:2.5::el9 |
|
Vendors & Products |
Redhat ansible Automation Platform
|
Thu, 27 Feb 2025 02:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat
Redhat service Mesh |
|
CPEs | cpe:/a:redhat:service_mesh:2.5::el8 | |
Vendors & Products |
Redhat
Redhat service Mesh |
Tue, 18 Feb 2025 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | dompurify: Mutation XSS in DOMPurify Due to Improper Template Literal Handling | |
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Fri, 14 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 14 Feb 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS). | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-02-14T00:00:00.000Z
Updated: 2025-02-14T15:30:49.790Z
Reserved: 2025-02-14T00:00:00.000Z
Link: CVE-2025-26791

Updated: 2025-02-14T15:30:43.141Z

Status : Received
Published: 2025-02-14T09:15:08.067
Modified: 2025-02-14T16:15:37.350
Link: CVE-2025-26791
