Vulnerability Description
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cure53 | Dompurify | < 2.4.2 |
Related Weaknesses (CWE)
References
- https://github.com/cure53/DOMPurify/commit/d1dd0374caef2b4c56c3bd09fe1988c347916Patch
- https://github.com/cure53/DOMPurify/security/advisories/GHSA-p3vf-v8qc-cwcrVendor Advisory
- https://lists.debian.org/debian-lts-announce/2025/02/msg00010.html
FAQ
What is CVE-2024-48910?
CVE-2024-48910 is a vulnerability with a CVSS score of 9.1 (CRITICAL). DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2.
How severe is CVE-2024-48910?
CVE-2024-48910 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-48910?
Check the references section above for vendor advisories and patch information. Affected products include: Cure53 Dompurify.