vulns.co
/
GKData.io MCP

DOMPurify / Cure53 · 2 min read

DOMPurify: accepted DOM realms must retain complete sanitization

CVE-2026-49458 describes a mismatch between accepting DOM objects from another realm and recognizing them during later sanitization. Checks tied to local constructor identity could omit protective decisions and subtree traversal. The general lesson is that admitting an input representation also commits the implementation to enforcing every required security check for that representation.

Open the reference Maintainer AdvisoryReviewed 2026-10-04

How to use this reference

Compare the set of accepted representations with the set covered by every protective decision, including nested content. Treat an unrecognized representation as an explicit policy decision rather than silently skipping validation. Review remediation and regression coverage together. These are conceptual review objectives, not a claim that any specific proposed implementation was shipped or independently tested.

Before reading

  • JavaScript realm and DOM object concepts
  • Sanitization, nested content and browser activation boundaries

Context and limits

  • The advisory requires attacker-influenced DOM from another same-origin realm, in-place sanitization and subsequent consumer activation. It excludes ordinary string input and same-realm in-place use from this issue.
  • It reports script execution with Chromium 148 and DOMPurify 3.4.5. Production compromise, account takeover and independent reproduction are not established here.
  • The advisory lists versions through 3.4.5 as affected and 3.4.6 as patched. This historical minimum is not a comprehensive current security guarantee.
  • The official 3.4.6 release describes stronger cross-realm and shadow-DOM checks plus expanded regression coverage. Its metadata records May 26, 2026 at 13:04:11 UTC; that software-release time is separate from the unknown resource-edition date. Advisory suggestions are not evidence of exact shipped implementation.
  • The advisory credits offset as Reporter. cure53 is the publishing account, not an explicit article byline, so authors remains empty. Release-wide thanks to offset and Bankde do not establish both as reporters of this particular advisory.

Sources and provenance

  1. Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound instanceof checks DOMPurify / Cure53 · reviewed 2026-10-04
  2. DOMPurify 3.4.6 DOMPurify / Cure53 · reviewed 2026-10-04
  3. Official DOMPurify 3.4.6 release metadata DOMPurify / Cure53 via GitHub · reviewed 2026-10-04

Record reviewed 2026-10-04. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software