A vulnerability classified as problematic has been found in cure53 DOMPurify up to 3.3.x. Impacted is an unknown function. This manipulation causes cross site scripting.
This vulnerability is registered as CVE-2026-41239. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.