
I'm pleased to share that CVE-2026-41238 has been assigned to a Prototype Pollution >> XSS vulnerability I identified in DOMPurify, affecting versions 3.0.1 through 3.3.3. If your web application renders user-supplied HTML, there's a very good chance it relies on DOMPurify. With 24m downloads per week, it's the de facto HTML sanitiser for the JavaScript ecosystem — used across React, Vue, Angular and Node.js applications. Only 10 prior CVEs across 7 years speaks to the quality of the library and the rigour of its maintainers at Cure53. The issue was patched in version 3.4.0. Coordinated disclosure handled through Cure53 — thanks to the team for a smooth process. Full technical writeup and GHSA below. Write-up https://labs.trace37.com/blog/dompurify-pp-ceh-bypass/ GHSA https://github.com/cure53/DOMPurify/security/advisories/GHSA-v9jr-rg53-9pgp
Post summary
CVE‑2026‑41238 is a prototype‑poly‑ing derived XSS flaw in DOMPurify through versions 3.0.1‑3.3.3; the issue was disclosed with a technical write‑up and patched in 3.4.0.
