DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).
History

Wed, 16 Apr 2025 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift_ai:2.19::el8

Fri, 28 Mar 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat openshift Ai
CPEs cpe:/a:redhat:openshift_ai:2.16::el8
Vendors & Products Redhat openshift Ai

Wed, 12 Mar 2025 07:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat ansible Automation Platform
CPEs cpe:/a:redhat:ansible_automation_platform:2.5::el8
cpe:/a:redhat:ansible_automation_platform:2.5::el9
Vendors & Products Redhat ansible Automation Platform

Thu, 27 Feb 2025 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat service Mesh
CPEs cpe:/a:redhat:service_mesh:2.5::el8
Vendors & Products Redhat
Redhat service Mesh

Tue, 18 Feb 2025 02:15:00 +0000

Type Values Removed Values Added
Title dompurify: Mutation XSS in DOMPurify Due to Improper Template Literal Handling
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 14 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 14 Feb 2025 08:30:00 +0000

Type Values Removed Values Added
Description DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-02-14T15:30:49.790Z

Reserved: 2025-02-14T00:00:00.000Z

Link: CVE-2025-26791

cve-icon Vulnrichment

Updated: 2025-02-14T15:30:43.141Z

cve-icon NVD

Status : Received

Published: 2025-02-14T09:15:08.067

Modified: 2025-02-14T16:15:37.350

Link: CVE-2025-26791

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-02-14T00:00:00Z

Links: CVE-2025-26791 - Bugzilla