CVE-2026-47423: DOMPurify XSS via selectedcontent re-clone
DOMPurify 3.4.4 allows selectedcontent by default, allowing a chain in which browsers “re-clone” an XSS payload after sanitization, effectively bypassing DOMPurify.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-47423 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →