CVE-2019-25155

URL Redirection to Untrusted Site ('Open Redirect') in npm/dompurify

Identifiers

GHSA-8hgg-xxm5-3873, CVE-2019-25155

Package Slug

npm/dompurify

Vulnerability

URL Redirection to Untrusted Site ('Open Redirect')

Description

DOMPurify before 1.0.11 allows reverse tabnabbing in demos/hooks-target-blank-demo.html because links lack a 'rel="noopener noreferrer"' attribute.

Affected Versions

All versions before 1.0.11

Solution

Upgrade to version 1.0.11 or above.

Last Modified

2023-11-16

source