Web Hack List

Collected research

Mutation XSS via namespace confusion - DOMPurify < 2.0.17 bypass

HTML drops a nested form on reparse, and mglyph stays in the MathML namespace when it is a direct child of mtext, so markup DOMPurify judges harmless parses differently the second time. Assigning the sanitized string to innerHTML turns inert text inside a style element into a live img with an onerror handler, giving mutation XSS through the sanitizer.

Record

Researcher
mibe
Published by
research.securitum.com
Date
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of mibe, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .