afterSanitizeElements of the component Custom Elements. The manipulation of the argument CUSTOM_ELEMENT_HANDLING.tagNameCheck leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-66010. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2026-66010 | cure53 DOMPurify up to 3.4.11 Custom Elements afterSanitizeElements CUSTOM_ELEMENT_HANDLING.tagNameCheck cross site scripting
Reagiere als Erste:r — dein Feedback zählt!
A vulnerability was found in cure53 DOMPurify up to 3.4.11. It has been rated as problematic. This affects the function
SOCIAL SHARE CARD GENERATOR