---
id: CVE-2026-65913
title: >-
  DOMPurify before 3.3.2 contains a prototype pollution vulnerability in
  USE_PROFILES mode that allows attackers to bypass attribute filtering by
  polluting Array.prototype properties
summary: >-
  DOMPurify before 3.3.2 contains a prototype pollution vulnerability in
  USE_PROFILES mode that allows attackers to bypass attribute filtering by
  polluting Array.prototype properties. Attackers can set Array.prototype
  properties like oncli…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-1321
vendor: cure53
product: dompurify
affected:
  - dompurify < 3.3.2
patched:
  - dompurify 3.3.2
published: '2026-07-23'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:30.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-65913'
references:
  - url: >-
      https://github.com/cure53/DOMPurify/security/advisories/GHSA-cj63-jhhr-wcxv
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/dompurify-before-prototype-pollution-via-use-profiles
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-07-23T13:38:17.202405Z'
epss: 0.00318
epssPercentile: 0.22675
ingestedAt: '2026-10-08T16:52:14.707Z'
---

## Overview

DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by polluting Array.prototype properties. Attackers can set Array.prototype properties like onclick to true, causing DOMPurify to accept event handlers as allowlisted attributes and resulting in DOM-based XSS when sanitized markup is rendered.

## Affected

- `dompurify < 3.3.2`

## Remediation

Upgrade past the affected range:

- `dompurify 3.3.2`
