{"id":"CVE-2025-15599","title":"DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting missing textarea rawtext element validation in the SAFE_FOR_XML regex…","summary":"DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting missing textarea rawtext element validation in the SAFE_FOR_XML regex…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"cure53","product":"dompurify","affected":["dompurify >= 2.5.3, <= 2.5.8","dompurify >= 3.1.3, < 3.2.7"],"patched":["dompurify 3.2.7"],"published":"2026-03-03","updated":"2026-10-08","sourceUpdated":"2026-10-08T16:16:50.390","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-15599","references":[{"url":"https://github.com/cure53/DOMPurify","label":"disclosure@vulncheck.com"},{"url":"https://github.com/cure53/DOMPurify/commit/c861f5a83fb8d90800f1680f855fee551161ac2b","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/dompurify-xss-via-textarea-rawtext-bypass-in-safe-for-xml","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-03-03T19:05:27.449675Z"},"epss":0.00249,"epssPercentile":0.149,"ingestedAt":"2026-10-08T16:52:14.673Z","slug":"CVE-2025-15599","body":"## Overview\n\nDOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting missing textarea rawtext element validation in the SAFE_FOR_XML regex. Attackers can include closing rawtext tags like </textarea> in attribute values to break out of rawtext contexts and execute JavaScript when sanitized output is placed inside rawtext elements. The 3.x branch was fixed in 3.2.7; the 2.x branch was never patched.\n\n## Affected\n\n- `dompurify >= 2.5.3, <= 2.5.8`\n- `dompurify >= 3.1.3, < 3.2.7`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `dompurify 3.2.7`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}