4 ms·
Because DOMPurify is not perfect. Due to some problem of HTML parsing, there were some ways to bypass it: https://research.securitum.com/mutation-xss-via-mathml
by maple3142 5y ago
Because DOMPurify is not perfect. Due to some problem of HTML parsing, there were some ways to bypass it: https://research.securitum.com/mutation-xss-via-mathml-mutation-dompurify-2-0-17-bypass/ https://research.securitum.com/mutation-xss-via-mathml-mutat...
Having a builtin XSS sanatizer means it could always use a single parser to prevent such bypass.