# CVE-2026-49458

## Summary

- **CVE ID:** CVE-2026-49458
- **Severity:** MEDIUM
- **CVSS Score:** 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
- **CWE:** CWE-79, CWE-501, CWE-693
- **Published:** Jul 14, 2026
- **Last Modified:** Jul 15, 2026

## Description

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accepted same-origin foreign-realm DOM nodes while follow-on checks used parent-realm constructors, causing instanceof checks for forms, named node maps, document fragments, and elements to fail and skip clobber, template-content, and shadow-DOM sanitization branches so executable markup could survive. This issue is fixed in version 3.4.6.

## Affected Products

- cure53 — DOMPurify (< 3.4.6)

## References

- [CNA](https://github.com/cure53/DOMPurify/security/advisories/GHSA-hpcv-96wg-7vj8)
- [CNA](https://github.com/cure53/DOMPurify/commit/bb7739e5bccec7e1ab3dae3f3e42d02db3acaaae)
- [CNA](https://github.com/cure53/DOMPurify/releases/tag/3.4.6)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.40%
- **EPSS Percentile:** 33.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._