In DOMPurify through 3.2.5 before 6bc6d60, scripts/server.js does not ensure that a pathname is located under the current working directory. NOTE: the Supplier disputes the significance of this report because the "Uncontrolled data used in path expression" occurs "in a development helper script which starts a local web server if needed and must be manually started."
References
Configurations
No configuration.
History
16 May 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary | (en) In DOMPurify through 3.2.5 before 6bc6d60, scripts/server.js does not ensure that a pathname is located under the current working directory. NOTE: the Supplier disputes the significance of this report because the "Uncontrolled data used in path expression" occurs "in a development helper script which starts a local web server if needed and must be manually started." |
16 May 2025, 14:43
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
16 May 2025, 02:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
15 May 2025, 20:16
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/cure53/DOMPurify/pull/1101 - |
15 May 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-15 16:15
Updated : 2025-05-16 15:15
NVD link : CVE-2025-48050
Mitre link : CVE-2025-48050
CVE.ORG link : CVE-2025-48050
JSON object : View
Products Affected
No product.
CWE
CWE-24
Path Traversal: '../filedir'