Web Hack List

Collected research

DOMPurify 2.0.0 bypass using mutation XSS

Write-up of DOMPurify 2.0.0 bypass using mutation XSS

A Chrome and Safari parsing quirk re-serializes markup so content nested inside an svg element jumps out of it when innerHTML is assigned to itself. Markup that DOMPurify judges harmless on first parse therefore mutates into an img carrying an onerror handler and executes script; math and br variants work the same way.

Record

Document
Write-up of DOMPurify 2.0.0 bypass using mutation XSS
Researcher
securitum
Published by
research.securitum.com
Date
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of securitum, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .