Top 10 winner
Exploring the DOMPurify library: Bypasses and Fixes
Chains HTML parser quirks, deep-nesting node flattening, insertion-mode popping, form and table reordering, and DOM clobbering of the sanitiser's own depth counter, into full mutation-XSS bypasses of three DOMPurify releases in default configuration, plus a payload that survives triple HTML parsing so it still fires when markup is parsed before sanitisation.
Record
- Researcher
- kevin_mizu
In the archive
Related sources
- DOMPurify research, part 2
- DOMPurify 3.1.2 live demonstration
- DOMPurify double-sanitization demonstration
Tags
This page is the archive's own catalogue record. The research is the work of kevin_mizu, first published at the original source. Preserved copies are kept so the citation survives its host.