Collected research
Mutation XSS via namespace confusion - DOMPurify < 2.0.17 bypass
HTML drops a nested form on reparse, and mglyph stays in the MathML namespace when it is a direct child of mtext, so markup DOMPurify judges harmless parses differently the second time. Assigning the sanitized string to innerHTML turns inert text inside a style element into a live img with an onerror handler, giving mutation XSS through the sanitizer.
Record
- Researcher
- mibe
- Published by
- research.securitum.com
- Date
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of mibe, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .