A vulnerability, which was classified as problematic, has been found in cure53 DOMPurify up to 3.4.6. This affects an unknown part. Performing a manipulation results in cross site scripting.

This vulnerability was named CVE-2026-65901. The attack may be initiated remotely. There is no available exploit.