Top 10 winner
Exploring the DOMPurify library: Bypasses and Fixes
Exploring the DOMPurify library: Bypasses and Fixes (1/2)
Chains HTML parser quirks, deep-nesting node flattening, insertion-mode popping, form and table reordering, and DOM clobbering of the sanitiser's own depth counter, into full mutation-XSS bypasses of three DOMPurify releases in default configuration, plus a payload that survives triple HTML parsing so it still fires when markup is parsed before sanitisation.
Record
- Document
- Exploring the DOMPurify library: Bypasses and Fixes (1/2)
- Researcher
- kevin_mizu
- Published by
- mizu.re
- Topic
- Browser
In the archive
Related sources
- DOMPurify research, part 2
- DOMPurify 3.1.2 live demonstration
- DOMPurify double-sanitization demonstration
Tags
This page is the archive's own catalogue record. The research is the work of kevin_mizu, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .