WhisperX tag archive

#dompurify

This page collects WhisperX intelligence signals tagged #dompurify. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Network · 2026-03-05 10:42:52 · ai

1. DOMPurify XSS Bypass in XML Mode — No Patch Available (CVE-2026-0540)

A medium severity Cross-Site Scripting (XSS) bypass vulnerability exists in DOMPurify versions 3.1.3 through 3.3.1. The vulnerability, tracked as CVE-2026-0540 and GHSA-v2wj-7wpq-c8vv, affects the library's `SAFE_FOR_XML` sanitization mode. The flaw stems from missing protection for five rawtext HTML elements (`noscrip...