CVE-2026-65901 (Medium) detected in dompurify-3.4.1.tgz

Open Beginner friendly
#377 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
74/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Quiet
Tech stack
javascript, react
Domain
frontend, security

Research direction

Start with /ui/package.json and trace the dependency path through react and monaco-editor to the vulnerable dompurify package. Update the resolved dependency to dompurify 3.4.7, then confirm the UI dependency metadata no longer resolves dompurify 3.4.1.

Written by the indexing model from the issue text.

Description

Mend: dependency security vulnerability

CVE-2026-65901 - Medium Severity Vulnerability

Vulnerable Library - dompurify-3.4.1.tgz

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It's written in JavaScript and works in all modern browsers (Safari, Opera (15+), Internet Explorer (10+), Firefox and Chrome - as well as almost anything else usin

Library home page: https://registry.npmjs.org/dompurify/-/dompurify-3.4.1.tgz

Sample Path to Dependency File: /ui/package.json

Path to vulnerable library: /ui/node_modules/.pnpm/dompurify@3.4.1/node_modules/dompurify/package.json

Dependency Hierarchy:

  • @⁠postgres.ai/ce-4.0.3.tgz (Root Library)
    • react-4.7.0.tgz
      • monaco-editor-0.55.1.tgz
        • dompurify-3.4.1.tgz (Vulnerable Library)

Found in base branch: master

Vulnerability Details

DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled nodeName on live non-form nodes. Attackers can supply hostile live DOM objects with real script children whose observable nodeName is clobbered to appear as allowed elements, causing scripts to execute when the sanitized tree is inserted into a live document.

Publish Date: 2026-07-23

URL: CVE-2026-65901

CVSS 3 Score Details (6.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-07-23

Fix Resolution: dompurify - 3.4.7,https://github.com/cure53/DOMPurify.git - 3.4.7


Step up your Open Source Security Game with Mend here

Dominant language
Go
Stars
2.7k
Forks
85
PR merge metrics
No merged PRs in 30d

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from postgres-ai/database-lab-engine

All issues in postgres-ai/database-lab-engine

Similar issues

More Go issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.