Web Hack List

Other nomination

DOMPurify 2.0.0 bypass using mutation XSS

A Chrome and Safari parsing quirk re-serializes markup so content nested inside an svg element jumps out of it when innerHTML is assigned to itself. Markup that DOMPurify judges harmless on first parse therefore mutates into an img carrying an onerror handler and executes script; math and br variants work the same way.

Record

Researcher
securitum
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of securitum, first published at the original source. Preserved copies are kept so the citation survives its host.