CVE-2026-41238Disclosure

LOWCVSS 6.9 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a prototype pollution-based XSS bypass. When an application uses `DOMPurify.sanitize()` with the default configuration (no `CUSTOM_ELEMENT_HANDLING` option), a prior prototype pollution gadget can inject permissive `tagNameCheck` and `attributeNameCheck` regex values into `Object.prototype`, causing DOMPurify to allow arbitrary custom elements with arbitrary attributes — including event handlers — through sanitization. Version 3.4.0 fixes the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-1321

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-20); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-20: 1Mentions · 2026-08-18: 1PoC Mentioned / Linked · 2026-04-20: 1Patch / Workaround · 2026-04-20: 1Technical Details · 2026-04-20: 104-2008-18
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-201
Disclosure1
2026-08-181
General1
Full discourse2 posts
  • trace37@trace37_labs
    Disclosure

    I'm pleased to share that CVE-2026-41238 has been assigned to a Prototype Pollution >> XSS vulnerability I identified in DOMPurify, affecting versions 3.0.1 through 3.3.3. If your web application renders user-supplied HTML, there's a very good chance it relies on DOMPurify. With 24m downloads per week, it's the de facto HTML sanitiser for the JavaScript ecosystem — used across React, Vue, Angular and Node.js applications. Only 10 prior CVEs across 7 years speaks to the quality of the library and the rigour of its maintainers at Cure53. The issue was patched in version 3.4.0. Coordinated disclosure handled through Cure53 — thanks to the team for a smooth process. Full technical writeup and GHSA below. Write-up https://labs.trace37.com/blog/dompurify-pp-ceh-bypass/ GHSA https://github.com/cure53/DOMPurify/security/advisories/GHSA-v9jr-rg53-9pgp

    Post summary

    CVE‑2026‑41238 is a prototype‑poly‑ing derived XSS flaw in DOMPurify through versions 3.0.1‑3.3.3; the issue was disclosed with a technical write‑up and patched in 3.4.0.

    412082597.3K
    1.0K followersView on X
  • trace37@trace37_labs
    General

    @thedawgyg CVE-2026-41238 ... the way us hackers greet each other these days!

    Post summary

    The text merely references CVE‑2026‑41238 with no further information.

    00020606
    1.0K followersView on X

Explore more