The identified library DOMPurify, version 3.3.2 is vulnerable.
Nobody has claimed this yet.
- Dominant language
- TypeScript
- Stars
- 25.9k
- Forks
- 2.4k
- Avg merge
- 13h 10m
- Merged PRs (30d)
- 4
Description
Describe the bug
The identified library DOMPurify, version 3.3.2 is vulnerable.
CVE-2026-41239
CVE-2026-41238
CVE-2026-41240
https://github.com/cure53/DOMPurify/releases/tag/3.4.0
Expected behavior
No cve's in the latest version
Minimal reproducible OpenAPI snippet(if possible)
N/A
Screenshots
If applicable, add screenshots to help explain your problem.
Additional context
Add any other context about the problem here.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No file or test is named. Search the dependency manifests for DOMPurify 3.3.2, review the 3.4.0 release and update the dependency, then run the repository's existing dependency and test checks. Done means the project uses DOMPurify 3.4.0 and the reported vulnerabilities are no longer present.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript, typescript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 62/100