Files
twenty/packages
Abdullah. e90fb4b55c fix(security): bump dompurify to 3.4.11 (config/hook pollution) (#21905)
## fix(security): bump dompurify to 3.4.11 (config/hook pollution)

Resolves [Dependabot Alert
#1520](https://github.com/twentyhq/twenty/security/dependabot/1520) and
[#1509](https://github.com/twentyhq/twenty/security/dependabot/1509).

### What

`dompurify` is affected by:
- **Permanent `ALLOWED_ATTR` pollution via `setConfig()`**
([#1520](https://github.com/twentyhq/twenty/security/dependabot/1520),
Moderate, `<= 3.4.10`)
- **Trusted Types policy survives `clearConfig()`**
([#1509](https://github.com/twentyhq/twenty/security/dependabot/1509),
Low, `< 3.4.9`)

Both patched in `3.4.11`. Bumps the direct `twenty-server` dep `^3.4.0
-> ^3.4.11`.

### Compatibility

Both advisories are about config/hook state pollution via
`setConfig`/`clearConfig`/hooks. All four of our call sites use plain
`DOMPurify(window).sanitize(...)` with **default config** — no
`setConfig`, `clearConfig`, `addHook`, `ALLOWED_ATTR`, or
`RETURN_TRUSTED_TYPE` — so we are not on the affected path, and the fix
does not change default-`sanitize` behavior.

Verification: `typecheck twenty-server` passes; the
`prepare-file-for-storage`, `create-html-to-text-converter`, and
`email-composer` suites pass (28 tests).

### Verification

- `dompurify` resolves to `3.4.11` (no `<= 3.4.10` remains).
- Lockfile + single package.json pin change; `yarn install --immutable`
passes.
2026-06-21 15:05:17 +02:00
..