Tag
dom-clobbering
Safeguard articles tagged "dom-clobbering" — guides, analysis, and best practices for software supply chain and application security.
2 articles
Application Security
DOM clobbering: the XSS attack that never runs a script tag
DOM clobbering lets attackers hijack JavaScript logic using pure HTML — no <script> tag required — and it just bypassed DOMPurify's own sanitizer in 2026.
Jul 8, 20266 min read
AppSec
PrismJS: Vulnerability History and Hardening Your Syntax Highlighting
The npm prismjs package has patched ReDoS, plugin XSS, and a DOM clobbering flaw over the years. Here is the full history and how to run a syntax highlighter safely.
Sep 2, 20256 min read
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.