CyberRota
Back to database

CVE-2026-41239

MEDIUM · CVSS 6.8 EPSS 0.05% Public Exploit

Source: NVD + CISA KEV + EPSS · Published: 2026-04-23 · Last synced: 2026-05-23

CyberRota Analysis

Detaylı analiz gerekiyor.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-41239
Severity
MEDIUM
CVSS
6.8
EPSS
0.05%

Original NVD Description

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TEMPLATES` strips `{{...}}` expressions from untrusted HTML. This works in string mode but not with `RETURN_DOM` or `RETURN_DOM_FRAGMENT`, allowing XSS via template-evaluating frameworks like Vue 2. Version 3.4.0 patches the issue.