Collected research
DOMPurify 2.0.0 bypass using mutation XSS
Write-up of DOMPurify 2.0.0 bypass using mutation XSS
A Chrome and Safari parsing quirk re-serializes markup so content nested inside an svg element jumps out of it when innerHTML is assigned to itself. Markup that DOMPurify judges harmless on first parse therefore mutates into an img carrying an onerror handler and executes script; math and br variants work the same way.
Record
- Document
- Write-up of DOMPurify 2.0.0 bypass using mutation XSS
- Researcher
- securitum
- Published by
- research.securitum.com
- Date
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of securitum, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .