#DOMPurify
I'm very happy to finally share the second part of my DOMPurify security research 🔥

This article mostly focuses on DOMPurify misconfigurations, especially hooks, that downgrade the sanitizer's protection (even in the latest version)!

Link 👇
mizu.re/post/explori...

1/2
February 10, 2025 at 5:57 PM
Read this! Beautiful blog post, and so much to learn from it

mizu.re/post/explori...
Exploring the DOMPurify library: Bypasses and Fixes. Tags:Article - Article - Web - mXSS
Exploring the DOMPurify library: Bypasses and Fixes
mizu.re
November 15, 2024 at 5:30 PM
would you believe that “dompurify for css” was an area of active research that i dropped because we really didn’t have time for that on top of The Rest Of Running Cohost
December 29, 2025 at 12:06 AM
We’re donating to DOMPurify as part of our open source donation program. DOMPurify, built and maintained by Cure53, is the best tool to protect your website from XSS attacks.

They are doing an amazing job at tracking all new potential attacks. We respect and rely on their findings.
As part of our OSS donation program, this month we're celebrating @gregberge.com.

He’s the maintainer of ~20 OSS projects, including SVGR.

SVGR transforms SVG files into React components. It also works with Webpack, Vite, and Next.js.
We use @devongovett.me's tools across our projects. We particularly rely on React Aria to make our tools accessible.

As part of our open source donation program, we donated to Devon to thank him for his work and impact on the community.

He's also the creator of Parcel and Lightning CSS.
September 14, 2026 at 3:23 PM
dompurify is so annoying like i have multiple bugs that almost bypass but are stopped by just how many precautions it takes aaaaaaa
July 22, 2026 at 9:47 AM
I would be glad to be included on the list! I think my best article so far is about the recent DOMPurify bypasses :D
Exploring the DOMPurify library: Bypasses and Fixes. Tags:Article - Article - Web - mXSS
Exploring the DOMPurify library: Bypasses and Fixes
mizu.re
December 1, 2024 at 9:58 PM
Exploring the DOMPurify library: Hunting for Misconfigurations mizu.re/post/explori...
Exploring the DOMPurify library: Hunting for Misconfigurations (2/2). Tags:
Exploring the DOMPurify library: Hunting for Misconfigurations (2/2)
mizu.re
February 10, 2025 at 6:49 PM
I've pushed some updates to Dom-Explorer:
- Allow multiple pipeline embed
- Short links for sharing/sync
- Support for DomPurify triggers
- User settings

Give it a try and share your findings!

yeswehack.github.io/Dom-Explorer
Dom-Explorer
yeswehack.github.io
December 20, 2024 at 1:54 PM
Making CSP (Content Security Policy) and Trusted Types work in Rimmel.js with DOMPurify

#javascript #frontend #buildinpublic #ui #cybersecurity

stackblitz.com/edit/rimmel-...
A SafeHTML Sink for Rimmel.js powered by DOMPurify - StackBlitz
Using DOMPurify to clean untrusted input
stackblitz.com
November 28, 2025 at 11:46 PM
Huge shoutout to @mizu.re for this awesome research and cosmic bypasses👇
Exploring the DOMPurify library: Bypasses and Fixes (1/2). Tags:Article - Article - Web - mXSS
Exploring the DOMPurify library: Bypasses and Fixes (1/2)
mizu.re
May 13, 2025 at 9:03 AM
Firefox nightly introduces the setHTML() method. Which is like a native DOMPurify. You can easily test it here:
portswigger-labs.net/mxss/

Set HTMLSanitizer ✅
Auto update ✅

I'm trying to break it, I encourage you to break it too
November 3, 2025 at 12:26 PM
Thanks to the recent @portswiggerres.bsky.social top 10, I finally found the motivation to finish writing the 2nd article about DOMPurify security! 😁

Before releasing it, I would like to share a small challenge 🚩

Challenge link 👇
challenges.mizu.re/xss_04.html

1/2
February 7, 2025 at 4:34 PM
The Sanitizer API: Safe HTML Injection Without DOMPurify #js
The Sanitizer API: Safe HTML Injection Without DOMPurify
The browser can now strip XSS from an HTML string during parsing. Here's how setHTML works, why its config can only narrow the allowlist, and how to ship it before Safari catches up.
danholloran.me
August 3, 2026 at 7:07 AM
November 24, 2024 at 4:51 PM
Looks like my DOMPurify article has been nominated! I know I haven't released part 2 yet, but if you enjoyed it, I would really appreciate if you could vote for it! 🫶

mizu.re/post/explori...
Voting is now live for the Top Ten (New) Web Hacking Techniques of 2024! Browse the nominations & cast your votes here: portswigger.net/polls/top-10...
Top 10 web hacking techniques of 2024
Welcome to the community vote for the Top 10 Web Hacking Techniques of 2024.
portswigger.net
January 16, 2025 at 8:53 AM
I don't even give a fuck anymore 😶
November 27, 2024 at 6:15 PM
P2/3 🧙‍♂️🪄
www.youtube.com/watch?v=KffI...
November 23, 2024 at 6:07 PM
How I Chained Three Bugs to XSS an Intigriti CTF — IDOR + DOM Clobbering + DOMPurify 3.0.9 Bypass
How I Chained Three Bugs to XSS an Intigriti CTF — IDOR + DOM Clobbering + DOMPurify 3.0.9 Bypass
Intigriti May 2026 XSS Challenge — full write-up
infosecwriteups.com
August 26, 2026 at 5:11 AM
A security update for Wiki.js 2.5.308 was just released.

Includes:
- Update dompurify (HTML sanitize module) to the latest version
- Add groups mapping for the Azure AD auth module
- Fix code wrapping in print view

See github.com/requarks/wik... for details.
Release v2.5.308 · requarks/wiki
✨ New Features c093423 - set groups based on Azure groups (PR #7736 by @pianosaurus) 🐛 Bug Fixes 86abfea - update dompurify dependency + add cross-env (commit by @NGPixel) 1b6c67e - force wrap f...
github.com
August 13, 2025 at 7:45 AM
DOMPurify 3.4.1 is out with lots of small improvements.

Among them, a better test suite, a small fuzzer, several fixes and hardenings, and as usually we hope all went well 😅

https://github.com/cure53/DOMPurify/releases/tag/3.4.1
Release DOMPurify 3.4.1 · cure53/DOMPurify
Fixed an issue with on-handler stripping for HTML-spec-reserved custom element names (font-face, color-profile, missing-glyph, font-face-src, font-face-uri, font-face-format, font-face-name) under ...
github.com
April 21, 2026 at 4:46 PM
haha yeah a good reminder 😝 did a quick and dirty regex fix now (apparently neither dompurify nor isomorphic-dompurify work in cloudflare workers ^^) and will figure out something better later (really should switch to cookie based auth i guess)
January 30, 2026 at 12:34 AM
P1/3 : DomPurify & Bootstrap n-days + Frontend tricks Ft. @geluchat.bsky.social @mizu.re 😘
www.youtube.com/watch?v=fnYS...
EP 163 | DomPurify & Bootstrap n-days + Frontend tricks Ft. @Geluchat, @kevin_mizu
YouTube video by Laluka
www.youtube.com
November 22, 2024 at 4:58 PM
I was keeping this one for myself for a while, but after several discussions at DefCon I thought it would be nice to share it now :)

Btw! If you wonder how could this be abused, I recommend you looking at: mizu.re/post/explori... 😉

3/3
Exploring the DOMPurify library: Hunting for Misconfigurations (2/2). Tags:Article - Article - Web - mXSS
Exploring the DOMPurify library: Hunting for Misconfigurations (2/2)
mizu.re
August 25, 2025 at 4:17 PM