DOMPurify, DOM XSS via IN_PLACE Rawtext Root Return, GHSA-6688-9rhm-gjv2 (Low) -DC-Oct2026-2745

Listen to this Post

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. The vulnerability resides in the IN_PLACE sanitization mode of DOMPurify 3.4.15. When an application calls `DOMPurify.sanitize(node, { IN_PLACE: true })` on a Node input, the sanitizer processes the caller’s live DOM subtree directly. The 3.4.9 fix for the IN_PLACE detached-root class added two protections on the IN_PLACE return path: a fail-closed `TypeError` in `_forceRemove` when a node selected for removal cannot be detached, and a `_neutralizeSubtree` pass (dist/purify.js line 1336) that strips non-allowlisted attributes from removed subtrees. Both protections miss the rawtext text-content form. When the force-removed root is a rawtext element such as <style>, the payload lives in the node’s text: the node detaches fine (the `TypeError` guard is not reached), `_neutralizeSubtree` strips nothing (there are no attributes), and the IN_PLACE exit returns the detached, never-sanitized `