lowVulnerability

GHSA-p98j-92pf-mc4p

## Summary In `IN_PLACE` mode DOMPurify sanitizes the caller's live DOM subtree directly. To close a known hazard (GHSA-55q2-fjhq-7xh7), the library neutralizes any node a hook detaches during sanitization by stripping its subtree's non-allow-listed attributes, but this neutralization is wired only into the `beforeSanitizeElements` and `uponSanitizeElement` hook sites. An `afterSanitizeElements` or `afterSanitizeAttributes` hook that removes a non-root element (a documented, supported pattern) detaches that element's subtree with no neutralization, so descendant `on*` handlers remain armed on the caller's live tree after `sanitize()` returns, yielding DOM XSS. No special privilege is required beyond supplying markup to an application that uses `IN_PLACE` together with a node-removing afterSanitize hook. ## Root Cause `IN_PLACE` sanitization mutates the caller's live document, so any element a hook detaches from that tree must have its subtree neutralized before `sanitize()` returns; otherwise a queued resource-event handler (for example an `<img onerror>` that began loading when the caller built the tree) fires in page scope even though the handler never reached the sanitized output. The guard helper `_handleHookDetachedNode` (which calls `_neutralizeSubtree` in `IN_PLACE`) is invoked only after `beforeSanitizeElements` and after `uponSanitizeElement`. It is never invoked from the afterSanitize return paths, and `_sanitizeAttributes` never calls it at all. The post-walk `IN_PLACE` neutralization pass iterates only `DOMPurify.removed`, and hook-detached nodes are intentionally not recorded there, so that pass cannot reach them either. ```text src/purify.ts _sanitizeElements: _handleHookDetachedNode present at lines 2142 and 2175 (before/upon), absent after afterSanitizeElements at lines 2208 and 2249. _sanitizeAttributes: afterSanitizeAttributes fires at line 2670 with no detach re-check; the function never calls _handleHookDetachedNode. Post-walk I

Properties

ghsa_id
GHSA-p98j-92pf-mc4p
summary
DOMPurify: IN_PLACE: node-removing afterSanitize hook leaves detached subtree event handlers armed, causing DOM XSS
severity
low
last_source
GitHub Advisory Database
cve_id
GHSA-p98j-92pf-mc4p
signal_observed_at
2026-09-30T23:58:31+00:00
is_ghsa_only
true
retrieved_at
2026-09-30T23:58:31+00:00
ghsa_published
2026-09-30T15:37:57Z
source_url
https://github.com/advisories/GHSA-p98j-92pf-mc4p
ghsa_updated
2026-09-30T15:37:59Z

Related Entities (4)

VULNERABLE_TO (1)

←[Software]npm/dompurify

AFFECTS (1)

→[Software]npm/dompurify

REPORTED_BY (1)

→[Source]GitHub Advisory Database

HAS_WEAKNESS (1)

→[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-p98j-92pf-mc4p — Ninja Signal Threat Intelligence | Ninja Signal