Skip to content

project

DOMPurify

HTML sanitizer used by the extension after an earlier XSS fix, configured with an allowlist that preserved script-like diagram types.

Known aliases

  • isomorphic-dompurify

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

One fetch as Googlebot exposed the empty shell behind 270 unindexed articles

Googlebot got 0 characters inside a client-rendered blog's root div, its developer found after Google crawled 270 of the posts and indexed none. A bot-only branch in an existing Netlify edge function now hands crawlers the rendered article and JSON-LD.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence50
build1 publisher

An <object> tag turns an uploaded SVG into stored XSS for every visitor

OopsSec Store, a deliberately vulnerable Next.js app, lets an admin-uploaded SVG run JavaScript in every visitor's browser. It works because the server trusts the client-set Content-Type and the product page renders SVGs through an <object> tag.

Publishers:dev.to

Reality

Evidence62
Adoption
Insufficient
Hype gap+8
Incentives40
Confidence72
build1 publisher

A CSP directive turns every string passed to innerHTML into a TypeError

MDN now lists the Trusted Types API as Baseline 2026, newly available. The JavaScript half only lets you sanitize; require-trusted-types-for is the part that makes an unsanitized assignment throw, and the sanitizer stays yours to write.

Publishers:developer.mozilla.org

Reality

Evidence70
Adoption
Insufficient
Hype gap+8
Incentives22
Confidence63