CVE-2026-65902 | DOMPurify up to 3.4.5 Hooks sanitize allowedTags/allowedAttributes Remote Code Execution

SecurityVulns

A vulnerability classified as critical was found in DOMPurify up to 3.4.5. This impacts the function sanitize of the component Hooks. Executing a manipulation of the argument allowedTags/allowedAttributes can lead to Remote Code Execution.

This vulnerability is tracked as CVE-2026-65902. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is advised.VulDB Recent EntriesRead More