A vulnerability has been found in cure53 DOMPurify up to 3.3.1 and classified as problematic. Affected is an unknown function. Performing a manipulation results in cross site scripting.
This vulnerability is identified as CVE-2026-41238. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.