Bypassing DOMPurify again with mutation XSS
portswigger.net | research | #firefox | #web-security | #chrome | #dompurify | #mutation-xss | #sanitizer-bypass
Summary
A fresh mutation XSS bypass of DOMPurify's patch: crafted comments and encoded tags mutate sanitized markup into executable XSS in Chrome, plus a CDATA variant for Firefox; fixed in DOMPurify 2.1.
- Published
- Collected
Skip to content