DOMPurify XSS via Textarea Rawtext Bypass in SAFE_FOR_XML
Vulnerability Description
DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting missing textarea rawtext element validation in the SAFE_FOR_XML regex. Attackers can include closing rawtext tags like </textarea> in attribute values to break out of rawtext contexts and execute JavaScript when sanitized output is placed inside rawtext elements. The 3.x branch was fixed in 3.2.7; the 2.x branch was never patched.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-15599
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Scott Moore - VulnCheck
References
More from cure53
View All →Affected Vendor
cure53
View all reports →