Description

DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).

INFO

Published Date :

2025-02-14T00:00:00.000Z

Last Modified :

2025-02-14T15:30:49.790Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-26791 vulnerability.

Vendors Products
Cure53
  • Dompurify
Redhat
  • Ansible Automation Platform
  • Network Observ Optr
  • Openshift Ai
  • Rhdh
  • Service Mesh

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact