GHSA-p98j-92pf-mc4p
## Summary In `IN_PLACE` mode DOMPurify sanitizes the caller's live DOM subtree directly. To close a known hazard (GHSA-55q2-fjhq-7xh7), the library neutralizes any node a hook detaches during sanitization by stripping its subtree's non-allow-listed attributes, but this neutralization is wired only into the `beforeSanitizeElements` and `uponSanitizeElement` hook sites. An `afterSanitizeElements` or `afterSanitizeAttributes` hook that removes a non-root element (a documented, supported pattern) detaches that element's subtree with no neutralization, so descendant `on*` handlers remain armed on the caller's live tree after `sanitize()` returns, yielding DOM XSS. No special privilege is required beyond supplying markup to an application that uses `IN_PLACE` together with a node-removing afterSanitize hook. ## Root Cause `IN_PLACE` sanitization mutates the caller's live document, so any element a hook detaches from that tree must have its subtree neutralized before `sanitize()` returns; otherwise a queued resource-event handler (for example an `<img onerror>` that began loading when the caller built the tree) fires in page scope even though the handler never reached the sanitized output. The guard helper `_handleHookDetachedNode` (which calls `_neutralizeSubtree` in `IN_PLACE`) is invoked only after `beforeSanitizeElements` and after `uponSanitizeElement`. It is never invoked from the afterSanitize return paths, and `_sanitizeAttributes` never calls it at all. The post-walk `IN_PLACE` neutralization pass iterates only `DOMPurify.removed`, and hook-detached nodes are intentionally not recorded there, so that pass cannot reach them either. ```text src/purify.ts _sanitizeElements: _handleHookDetachedNode present at lines 2142 and 2175 (before/upon), absent after afterSanitizeElements at lines 2208 and 2249. _sanitizeAttributes: afterSanitizeAttributes fires at line 2670 with no detach re-check; the function never calls _handleHookDetachedNode. Post-walk I
Properties
- ghsa_id
- GHSA-p98j-92pf-mc4p
- summary
- DOMPurify: IN_PLACE: node-removing afterSanitize hook leaves detached subtree event handlers armed, causing DOM XSS
- severity
- low
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-p98j-92pf-mc4p
- signal_observed_at
- 2026-09-30T23:58:31+00:00
- is_ghsa_only
- true
- retrieved_at
- 2026-09-30T23:58:31+00:00
- ghsa_published
- 2026-09-30T15:37:57Z
- source_url
- https://github.com/advisories/GHSA-p98j-92pf-mc4p
- ghsa_updated
- 2026-09-30T15:37:59Z
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
REPORTED_BY (1)
HAS_WEAKNESS (1)
Explore deeper with Ninja Signal's threat intelligence graph