#915·dillinger

Vulnerability in dillinger project

Author: ankitdnCreated Apr 6, 2026Updated Apr 6, 2026

While working on dillinger project, I scanned the dependency manifest and found that it uses a vulnerable version of dompurify. The scan revealed a URI validation bypass issue where custom attribute predicates can skip protocol checks, potentially allowing unsafe values like javascript: to pass through sanitization and lead to DOM-based XSS.

CVE Report CVE Link