NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #1052 most downloaded on npm
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It runs as JavaScript and works in all modern browsers, as well as in Node.js (via jsdom). DOMPurify is written by security people who have vast background in web a
Last release 11 days ago
23 Sep 2026
Release timing varies
gaps range from 2 weeks to 3 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
4 versions withdrawn
withdrawn after publishing
12 years old
153 releases · first in 2014
Added support for more attributes (srcset, crossdorigin etc.)
srcset, crossdorigin etc.)ALLOWED_URI_REGEXPMade DOMPurify be fully CSP compliant
Fixed various issues with the node.js loader Fixed various issues with the test-suite
One column per quarter.
Fixed various issues with the node.js loader Fixed various issues with the test-suite
*Refactored DOMPurify to ES2016/ES2017*
Fixed and worked around newly discovered variations of the Safari 10.1 - 10.2 XSS
Fixed another aspect of the Safari XSS
Nothing published for this version
Cleaned up after Safari emergency fix
Big thanks go to Egor Karbutov @ShikariSenpai and Egor Saltykov @ansjdnakjdnajkd for spotting and reporting the Safari issue to FastMail!
Fixed an XSS in Safari 10.1 and 10.2 introduced by a Safari browser bug
new DOMParser().parseFromString('<svg onload=alert(document.domain)>', 'text/html');FORCE_BODY to enable better handling of HTML starting with style and other elements a browser might move into the header (see #199)Allowed users to pass DOM nodes for sanitization
Made the uponSanitizeElement and uponSanitizeAttribute hooks more powerful (see #184)
Reduced the NPM package footprint
Fixed a bug with the handling of binary attributes
Added more tests to cover the security fix
ALLOW_UNKNOWN_PROTOCOLS is true (not the default) reported and addressed by @neiljAdded DOMPurify.removed to allow analyzing what elements and attributes were removed
DOMPurify.removed to allow analyzing what elements and attributes were removedMoved handling of URI-attributes from black-list to white-list
data-* attributes become URI-safeSAFE_FOR_TEMPLATING mode, spotted by @filedescriptorBetter fall-back handling for IE8 and IE9
Added SAFE_FOR_TEMPLATES flag to aggressively scrub template delimiters and content
SAFE_FOR_TEMPLATES flag to aggressively scrub template delimiters and contentAdded tests for document.write() behavior
document.write() behaviorAdded better compatibility for older browsers
/dist folder with a tested compressed DOMPurify versionSecurity Release Please update!
document.implementation by DOMParser.parseFromString()purify.js from / to /srcProblem: https://bugzilla.mozilla.org/show_bug.cgi?id=1205631
Attack Scenario:
The bug only manifested itself if the sanitized HTML DOMPurify created would be written to a document using document.write() or alike. Applications, that set the sanitized HTML by using innerHTML or outerHTML are not affected at all. Applications that do not allow SVG are also not affected at all.
The security issue is caused by a non-standard behavior of Gecko (the Firefox browser-engine) and a peculiar way of working with innerHTML-assignments. The following code snippets illustrate the issue:
<script>
// This is SAFE (but shouldn't be!)
document.body.innerHTML='<svg><p><style><img src="</style><img src=x onerror=alert(1)//">'
</script>
<script>
// This is UNSAFE
document.write('<svg><p><style><img src="</style><img src=x onerror=alert(1)//">')
</script>
Users who install this latest release are not affected by the bug anymore as DOMPurify fixes around the problem and mitigates the issue by not trusting Gecko's innerHTML implementation any much longer. Instead of the combination of document.implementation and doc.body.outerHTML, DOMPurify is now using the DOMParser feature available in all modern browsers.
This change is expected to be non-breaking, no API changes or other side-effects are expected.
Thanks @mozfreddyb for assisting with this fix.
Fixed around an MSIE/Edge bug causing freezes #89
New URI scheme white-list demo hook
DOMPurify can now use a custom-made window object
Merged countless optimizations and beautifications by @neilj
RETURN_DOM flag thanks to @neiljAdded hook demo for MentalJS JavaScript sandbox
Fixed several security issues identified by a 3rd party code audit
Important: This is a feature-release, not a security update.
Important: This is a feature-release, not a security update.
FORBID_TAGS to blacklist specific tagsFORBID_ATTR to blacklist specific attributesFixed a minor DOM clobbering issue reported by @filedescriptor
document.all cannot be clobbered by avoiding typeofFixed a bug in the clobber detection potentially leading to XSS, thanks @avlidienbrunn
Add Common JS support for browserify (Node.js is not supported yet)
Add Common JS support for browserify (Node.js is not supported yet)
Fixed a security issue in WebKit/Blink leading to a bypass (discovered & reported by Tom Ritter of iSEC Partners)
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →