DOMPurify is a tool tracked across 1 threat cluster and 3 intelligence report mentions on ThreatCluster. First observed May 22, 2026; most recent activity May 22, 2026.
Recent analyses have uncovered multiple bypasses in the DOMPurify library, a widely used HTML sanitizer, which could lead to Cross-Site Scripting (XSS) vulnerabilities. The vulnerabilities stem from parsing and…