CVE-2026-0540Disclosure(cure53 / dompurify)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cure53 dompurify systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 2726c74, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, noembed, noframes, iframe) in the SAFE_FOR_XML regex. Attackers can include payloads like </noscript><img src=x onerror=alert(1)> in attribute values to execute JavaScript when sanitized output is placed inside these unprotected rawtext contexts.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dompurify

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-03-03); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
dompurify

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-03: 3Mentions · 2026-04-10: 1Mentions · 2026-06-02: 1Patch / Workaround · 2026-03-03: 2Technical Details · 2026-03-03: 303-0304-1006-02
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-033
Disclosure3
2026-04-101
General1
2026-06-021
Disclosure1
Full discourse5 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-0540 Cross-Site Scripting in DOMPurify 2.5.3-2.5.8 and 3.1.3-3.3.1 via Rawtext Elements https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-0540

    Post summary

    An XSS vulnerability (CVE‑2026‑0540) affecting specific DOMPurify versions is announced, providing basic technical details but no exploit or mitigation information.

    0001183
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-0540 DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 729097f, contain a cross-site scripting vulnerability that allows attackers to bypass attribute s… https://www.cve.org/CVERecord?id=CVE-2026-0540

    Post summary

    The snippet furnishes a standard CVE-2026-0540 disclosure, listing affected DOMPurify versions, describing an XSS flaw that bypasses attribute checks, and noting the fix commit, but it does not provide any PoC, exploit code, or evidence of active exploitation.

    00001199
    56.6K followersView on X
  • Fluid Attacks@fluidattacks
    Disclosure

    A zero-day in DomPurify was discovered by Camilo Vera &amp; Cristian Vargas (@FluidAttacks) and Scott Moore (@VulnCheckAI). As a CNA, we've assigned it ID CVE-2026-0540. Full details: 🔗 https://fluidattacks.com/es/advisories/daft. We have disclosed 236 #CVEs to date: 🔗 https://fluidattacks.com/advisories. https://t.co/eN7K5S6d6d

    Post summary

    FluidAttacks announced a newly identified zero‑day vulnerability in DomPurify, assigning it CVE-2026-0540 and providing a link to the advisory for further details.

    0000083
    869 followersView on X
  • kek@fishjojo69
    General

    https://blog.kek.cx/posts/how-i-accidentally-set-a-0day-in-a-national-olympiad/ :D Short analysis of CVE-2026-0540

    Post summary

    The note refers to a short analysis of CVE‑2026‑0540 but offers no proof‑of‑concept, exploit code, active exploitation evidence, patch information, or technical details.

    0000044
    22 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-0540 DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 729097f, contain a cross-site scripting vulnerability that allows attackers to bypass attribute s… https://www.cve.org/CVERecord?id=CVE-2026-0540 ----- Traducción: CVE-2026-0540 DOM… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑0540, a cross‑site scripting flaw in DOMPurify versions 2.5.3‑2.5.8 and 3.1.3‑3.3.1, and notes it was fixed in commit 729097f. No exploit code or active use in the wild is reported.

    0000040
    55 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcure53dompurify---

Explore more