
🚨*CVE* CVE-2026-49978 DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow contents attached … https://www.cve.org/CVERecord?id=CVE-2026-49978 ----- Traducción: CVE-2026-49978 DOM… http://infoflow.cloud`
Post summary
CVE‑2026‑49978 highlights a DOM‑only cross‑site scripting flaw in DOMPurify before version 3.4.7 where shadow DOM content may be inadequately sanitized.


