NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #1052 most downloaded on npm
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It runs as JavaScript and works in all modern browsers, as well as in Node.js (via jsdom). DOMPurify is written by security people who have vast background in web a
Last release 11 days ago
06 Sep 2026
Release timing varies
gaps range from 2 weeks to 3 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
4 versions withdrawn
withdrawn after publishing
12 years old
152 releases · first in 2014
Fixed a licensing issue spotted and reported by @george-thomas-hill
Fixed a bypass in jsdom 22 in case the noframes element is permitted, thanks @leeN
noframes element is permitted, thanks @leeNFixed a problem with improper reset of custom HTML options, thanks @ammaraskar
One column per quarter.
Added support for ALLOW_SELF_CLOSE_IN_ATTR flag, thanks @edg2s @AndreVirtimo
ALLOW_SELF_CLOSE_IN_ATTR flag, thanks @edg2s @AndreVirtimoshadowrootmode, thanks @mfreed7Final release that is compatible with MSIE10 & MSIE 11
Fixed a Trusted Types sink violation with empty input and NAMESPACE , thanks @tosmolka
Added new config option ALLOWED_NAMESPACES for better XML handling, thanks @kevin-deyoungster @tosmolka
ALLOWED_NAMESPACES for better XML handling, thanks @kevin-deyoungster @tosmolkaSAFE_FOR_TEMPLATES is trueRemoved bundled types again as they caused too much trouble
Fixed an issue in 2.3.11 causing errors w. TypeScript, see #712, thanks @Mirco469, @brentkeller, @aryanisml
Added generated type definitions for better compatibility
Added support for sanitization of attributes requiring Trusted Types, thanks @tosmolka
Made TAG and ATTR config options case-sensitive when parsing XHTML, thanks @tosmolka
Cleaned up a minor issue with the 2.3.7 release, thanks @johnbirds
No other changes compared to 2.3.7 release, which entail:
Nothing published for this version
Added an option to allow HTML5 doctypes, thanks @tosmolka
Performed several chores and cleanups, thanks @is2ei
Added support for Custom Elements, thanks @franktopel
feImage elements, thanks @ydanivFixed a bug in the handing of PARSER_MEDIA_TYPE spotted by @securitum-mb
PARSER_MEDIA_TYPE spotted by @securitum-mbAdded new config option PARSER_MEDIA_TYPE, thanks @tosmolka
PARSER_MEDIA_TYPE, thanks @tosmolkaAdded code to make FORBID_CONTENTS setting configurable
FORBID_CONTENTS setting configurablerole to URI-safe attributesAdded better handling of document creation on Firefox
Fixed some minor issues related to the NAMESPACE config
NAMESPACE configAdded NAMESPACE config option, thanks @NateScarlet
NAMESPACE config option, thanks @NateScarletFixed handling of unsupported browsers, i.e. Safari 9 and older
Added new mXSS prevention logic created by SecurityMB
Nothing published for this version
Fixed a new MathML-based bypass submitted by PewGrand
_forceRemove logic for better reliabilityFixed an mXSS issue reported by PewGrand
Fixed an mXSS bypass dropped on us publicly via #482
Nothing published for this version
Fix a possible XSS in Chrome that is hidden behind _#enable-experimental-web-platform-features_, reported by @neilj and @mfreed7
RETURN_DOM_IMPORT default to true to address said possible XSSRETURN_DOM_IMPORT back to falseRemoved some code targeting old Safari versions
Fixed several possible mXSS patterns, thanks @hackvertor
SAFE_FOR_JQUERY flag (we are safe by default now for jQuery)Fixed another bypass causing mXSS by using MathML
Fixed an mXSS-based bypass caused by nested forms inside MathML
Credits for the bypass go to Michał Bentkowski (@securityMB) of Securitum who spotted the bug in Chrome, turned it into another DOMPurify bypass, reported and helped verifying the fix :bowing_man: :bowing_woman:
Added a renovated test suite, thanks @peernohell
Fixed a problem with the documentMode default value
Nothing published for this version
Fixed a minor bug when working with Trusted Types
Fixed faulty behavior for non breaking space characters
ADD_DATA_URI_TAGS directive to allow customizing Data URI tag behaviorFixed a dependency problem causing builds to break
Removed a meanwhile useless parser check
Fixed a bypass that can be abused in case SAFE_FOR_JQUERY is used with jQuery 3.x, thanks @masatokinugawa :bowing_woman:
SAFE_FOR_JQUERY is used with jQuery 3.x, thanks @masatokinugawa :bowing_woman:uponSanitizeAttribute, thanks @devinrhode2Fixed several mXSS vectors spotted , thanks @masatokinugawa :bowing_man:
Enhanced the checks for SVG-/MathML-based mXSS
Fixed a logical issue causing overly aggressive SVG removal spotted by @thorn0
Another mXSS variation was spotted by @masatokinugawa and got addressed and fixed in this release.
Another mXSS variation was spotted by @masatokinugawa and got addressed and fixed in this release.
The fixes were reviewed and no new bypasses could be spotted at the moment. Thanks, @masatokinugawa :bowing_man: :bowing_woman:!
The sanitization logic for this kind of mXSS was changed to be less aggressive and still be able to spot all recent mXSS variations we know about right now - while also avoiding risky string matching.
Prayers and thoughts that this was the final variation. But better be on the lookout for more releases soon.
Fixed another mXSS variation affecting Chrome, Safari and Edge relating to HTML templates
Credits for the bypass again go to Michał Bentkowski (@securityMB) of Securitum who spotted the bug in Chrome, turned it into another DOMPurify bypass, reported and helped verifying the fix :bowing_man: :bowing_woman:
Following the release of DOMPurify 2.0.1, a more thorough internal audit against Blink-based mXSS bugs was conducted. Several mXSS variations, spotted
Following the release of DOMPurify 2.0.1, a more thorough internal audit against Blink-based mXSS bugs was conducted. Several mXSS variations, spotted by @masatokinugawa were addressed and fixed. The fixes were reviewed and so far no new bypasses could be spotted.
This release manages to find what is believed to be a more holistic way to prevent mXSS bugs, specifically coming from HTML attributes and tags nested inside SVG and MathML.
Further, this release also addresses a DoS problem caused by sanitization of HTML tables when configured with potentially conflicting configuration settings.
Fixed a bypass affecting latest Chrome, caused by a newly discovered Chrome mXSS vulnerability
Credits go to Michał Bentkowski (@SecurityMB) of Securitum who spotted the bug in Chrome, turned it into a DOMPurify bypass, reported and helped verifying the fix. :bow:
Note: This release makes sure that, by default only string objects are returned (if not specified otherwise). This change relates to a surprising beha
Note: This release makes sure that, by default only string objects are returned (if not specified otherwise). This change relates to a surprising behavior in Chrome 77 - having to do with Trusted Types.
Fixed a minor problem with persistent config flags
Fixed a possible security problem when SAFE_FOR_TEMPLATES is true (default is false), thanks @masatokinugawa
SAFE_FOR_TEMPLATES is true (default is false), thanks @masatokinugawaALLOWED_TAGS or ADD_TAGS white-lists noembed or noscript (not the default), thanks @masatokinugawaExtended array of tested browsers
Recommended read, covering Trusted Types and compatibility implications: https://github.com/cure53/DOMPurify#what-about-dompurify-and-trusted-types
Reduced installed library footprint a bit
Fixed a bypass for older MS Edge found by Gareth Heyes / @hackvertor
Added new configuration flag IN_PLACE for very fast "in place" node sanitization
Added better test coverage for latest browsers
Added several more SVG attributes to white-list
Added support for more attributes (srcset, crossdorigin etc.)
srcset, crossdorigin etc.)ALLOWED_URI_REGEXPYour coding agent can read these notes before it upgrades. Set up the MCP server →