THREAT OPS › Threat News › [GHSA] GHSA-55q2-fjhq-7xh7 (medium) — DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS
[GHSA] GHSA-55q2-fjhq-7xh7 (medium) — DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS
GHSA-55q2-fjhq-7xh7 Severity: medium CVE: None
DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS
### Summary
During `IN_PLACE` sanitization, a hook that removes an element can leave that element's detached descendants executable. A descendant image can retain its attacker-provided `onload` handler and fire after `sanitize()` returns, even though the returned roo
MITRE ATT&CK techniques
- JavaScriptT1059.007
Original source: https://github.com/advisories/GHSA-55q2-fjhq-7xh7