Description
DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demonstrated by Chrome and Safari.
Remediation
References
https://lists.debian.org/debian-lts-announce/2020/10/msg00029.html
https://research.securitum.com/dompurify-bypass-using-mxss/
Related Vulnerabilities
CVE-2020-2226 Vulnerability in maven package org.jenkins-ci.plugins:matrix-project
CVE-2021-23356 Vulnerability in npm package kill-process-by-name
CVE-2021-46062 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2021-44550 Vulnerability in maven package edu.stanford.nlp:stanford-corenlp
CVE-2018-19797 Vulnerability in maven package org.webjars.npm:node-sass