CVE-2025-48050
In DOMPurify through 3.2.5 before 6bc6d60, scripts/server.js does not ensure that a pathname is located under the current working directory. NOTE: the Supplier disputes the significance of this report because the "Uncontrolled data used in path expression" occurs "in a development helper script which starts a local web server if needed and must be manually started."
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
- EPSS probability
- 0.47%
- CWE
- CWE-24
- Published
- 2025-05-15
- Last modified
- 2026-03-13
Affected products
- Cure53 DOMPurify
Weakness type
Related vulnerabilities
- CVE-2026-14947 — Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Remote Code Execution via malicious ZIP file
- CVE-2026-76353 — Path Traversal through Knowledge Bundle Replication in Splunk Enterprise
- CVE-2026-73573 — In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra...
- CVE-2026-48047 — XWiki Platform vulnerable to potential arbitrary file writing using path traversal from (subwiki) admin
- CVE-2026-66140 — Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and...
- CVE-2026-46687 — Emlog Local File Inclusion (LFI)
- CVE-2026-44942 — libzypp .repo files can have an optional path which can lead to path traversal attacks
- CVE-2026-49103 — Webmin before 2.640 does not safely construct a filename for saving of an attachment within the...