lowVulnerability

GHSA-vxr8-fq34-vvx9

## Impact A DOMPurify instance that is reused across trust boundaries can stay bound to a previously supplied `TRUSTED_TYPES_POLICY` even after `clearConfig()` is called. A later caller that requests `RETURN_TRUSTED_TYPE` receives a `TrustedHTML` object created by the old policy, not by a clean default configuration. If the old policy is unsafe or controlled by a less-trusted integration, this turns a later "default" sanitize call into script execution at a Trusted Types sink. `TRUSTED_TYPES_POLICY: null` on the later call also does not clear the retained policy. [dompurify-trusted-types-policy-survives-clearconfig-poc.js](https://github.com/user-attachments/files/28604913/dompurify-trusted-types-policy-survives-clearconfig-poc.js) ## Affected version Tested against DOMPurify `3.4.8`, repository commit `825e617753ac1169306a542d3174a77f717a0cf6`. ## Root cause `_parseConfig()` overwrites `trustedTypesPolicy` when `cfg.TRUSTED_TYPES_POLICY` is truthy, but the default/null path only initializes the internal policy when `trustedTypesPolicy === undefined`. Once a custom policy has been set, later default config parsing leaves it in place. Relevant code: - `src/purify.ts:786-812` accepts and stores `cfg.TRUSTED_TYPES_POLICY`. - `src/purify.ts:813-832` does not reset an existing policy when config has no policy or has `TRUSTED_TYPES_POLICY: null`. - `src/purify.ts:2123-2125` signs the final serialized HTML with the retained policy when `RETURN_TRUSTED_TYPE` is true. - `src/purify.ts:2133-2136` `clearConfig()` only clears `CONFIG` and `SET_CONFIG`; it does not reset `trustedTypesPolicy` or `emptyHTML`. ## Local PoC Run from the DOMPurify checkout, or set `DOMPURIFY_REPO`: ```bash node /home/dompurify-trusted-types-policy-survives-clearconfig-poc.js ``` Observed output: ```json { "result": { "baseline": "<b>baseline</b>", "duringPolicy": "<img src=x onerror=alert(\"TT_POLICY_SURVIVED_CLEARCONFIG\")>", "afterClearString": "<img src=\"x\">", "af

Properties

ghsa_id
GHSA-vxr8-fq34-vvx9
severity
low
summary
DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output
cve_id
GHSA-vxr8-fq34-vvx9
is_ghsa_only
true
ghsa_published
2026-06-15T20:12:53Z
source_url
https://github.com/advisories/GHSA-vxr8-fq34-vvx9
ghsa_updated
2026-06-15T20:12:54Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]npm/dompurify

AFFECTS (1)

[Software]npm/dompurify

HAS_WEAKNESS (1)

[Weakness]Protection Mechanism Failure

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-vxr8-fq34-vvx9 — Ninja Signal Threat Intelligence | Ninja Signal