Source: node-dompurify Version: 3.1.7+dfsg+~3.0.5-1 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team <t...@security.debian.org>
Hi, The following vulnerability was published for node-dompurify. CVE-2025-26791[0]: | DOMPurify before 3.2.4 has an incorrect template literal regular | expression, sometimes leading to mutation cross-site scripting | (mXSS). If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2025-26791 https://www.cve.org/CVERecord?id=CVE-2025-26791 [1] https://github.com/cure53/DOMPurify/commit/d18ffcb554e0001748865da03ac75dd7829f0f02 [2] https://ensy.zip/posts/dompurify-323-bypass/ Please adjust the affected versions in the BTS as needed. Regards, Salvatore -- Pkg-javascript-devel mailing list Pkg-javascript-devel@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel