Update npm package dompurify to v3.4.13 [SECURITY] - #9180
Update npm package dompurify to v3.4.13 [SECURITY]#9180hash-dependencies[bot] wants to merge 1 commit into
dompurify to v3.4.13 [SECURITY]#9180Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
PR SummaryLow Risk Overview This is a security-driven patch (GHSA-55q2-fjhq-7xh7) for XSS when Reviewed by Cursor Bugbot for commit 48ca32f. Bugbot is set up for automated code reviews on this repo. Configure here. |
This PR contains the following updates:
3.4.12→3.4.13DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS
GHSA-55q2-fjhq-7xh7
More information
Details
Summary
During
IN_PLACEsanitization, a hook that removes an element can leave that element's detached descendants executable. A descendant image can retain its attacker-providedonloadhandler and fire aftersanitize()returns, even though the returned root is clean and the image remains disconnected from the document.Details
In DOMPurify 3.4.12,
_sanitizeElements()insrc/purify.ts:1862-1904runs thebeforeSanitizeElementsoruponSanitizeElementhook and returns immediately when the hook detached the current node. The return does not call_neutralizeSubtree(currentNode).The detached subtree is not added to
DOMPurify.removed, so the post-walkIN_PLACEneutralization cannot reach it. If the browser queued a resource event while the application constructed the detached dirty root, a descendant can therefore retain its handler and execute after sanitization.The hook only rejects the containing element and does not add or approve the event handler. DOMPurify's ordinary removal path de-arms the same queued event; only the hook-detachment early return skips the existing subtree neutralization.
PoC
Load the published
dompurify@3.4.12dist/purify.jsbefore this script in Chromium:sanitize()returns with no handler execution and the returned root contains only the safediv. After the event loop advances, the original image remains disconnected but its retainedonloadchanges the page toXSS after sanitize.As the claim-matched control, use the same detached input with
ALLOWED_TAGS: ['div', '#text']and no hook. DOMPurify's ordinary removal path removes the original image's handler, the returned root is still<div>safe</div>, and the marker does not fire.Impact
In an application that uses
IN_PLACEwith the documented element-removal hook pattern, an attacker who can supply HTML can execute JavaScript in the integrating application's origin after the application sanitizes and renders that content.The required non-default configuration is
IN_PLACEplus a hook that removes a containing element. The hook does not add or approve the event handler, and the dirty root never needs to be connected before sanitization.Suggested fix
Reuse the existing
_neutralizeSubtree(currentNode)helper before returning from both hook-detachment branches in_sanitizeElements(). Add regressions forbeforeSanitizeElementsanduponSanitizeElementthat retain a reference to a descendant resource element and verify that its event handler is removed after the hook detaches its ancestor.Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
cure53/DOMPurify (dompurify)
v3.4.13: DOMPurify 3.4.13Compare Source
IN_PLACEsanitization, thanks @koyokrownerDocumentduringIN_PLACE, thanks @AkshayjainGConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR has been generated by Mend Renovate.