Cure53 🏳️‍🌈

And there is fire where we walk.

Cure53 🏳️‍🌈cure53@infosec.exchange
2026-03-05

DOMPurify 2.5.9 and DOMPurify 3.3.2 were released today in a rush to fix a security issue caused by jsdom's faulty tag parsing.

A total of four people reported the exacty same bug within a window of three days.

One did so via email, thank you. One did so via private security advisory, thank you too.

One however simply published a ticket for everyone to see, the other one just dropped a CVE on us without a working fix release. Thanks for nothing.

github.com/cure53/DOMPurify/re

github.com/cure53/DOMPurify/re

Cure53 🏳️‍🌈 boosted:
joernchen :cute_dumpster_fire:joern@threatactor.club
2026-03-02

Lands of Packets

TTL exceeded.

I would like to collect texts from the scene about FX in his memory. A collection of obituaries that will then be posted on phenoelit.de.

If anyone would like to contribute, please contact me.

Mail: joernchen@phenoelit.de
Signal: jrn.07

Cure53 🏳️‍🌈 boosted:
2026-03-02

RIP FX - You are a legend.

Here Dino is delivering his Pwnie Award, as well as the last public post FX made last year.

Cure53 🏳️‍🌈cure53@infosec.exchange
2026-02-19

@fluepke We frankly do not care, sorry not sorry 😅

From what can be seen, they don't call us "Partner" but just list us as a firm. So, not too triggered by all that overly much.

Thank you for the ping though, we had worse stuff being published in the past and then actually decided to do something against it.

Cure53 🏳️‍🌈cure53@infosec.exchange
2026-02-19

@fluepke @schrotthaufen We had no prior knowledge about this website until you mentioned us 😅

But also kind of don't really care.

Cure53 🏳️‍🌈cure53@infosec.exchange
2026-01-05

We have slightly updated the publicly available contract templates for NDA, MSA and DPA. File format is ODT as usual.

Feel free to, just as before, use them as you see it fit for your own purposes 😄

github.com/cure53/Contracts

Cure53 🏳️‍🌈cure53@infosec.exchange
2025-11-20

@GossiTheDog Proudly serving no cookies or whatsoever on cure53.de ever since the website went online.

We do receive mails from folks that complain about the missing banner though, assuming something is wrong.

Cure53 🏳️‍🌈cure53@infosec.exchange
2025-10-15

DOMPurify 3.3.0 is out. You can now configure which tags can have which attributes much more easily.

github.com/cure53/DOMPurify/re

Thanks again to everyone who contributed to and supported the project. ❤️

Cure53 🏳️‍🌈cure53@infosec.exchange
2025-10-09

DOMPurify 3.3.0 will soon be released, with this likely being the most important change in a long time:

github.com/cure53/DOMPurify/pu

Cure53 🏳️‍🌈cure53@infosec.exchange
2025-10-09

@ll1t So, basically what we already do, just about chest hair, not websites.

Cure53 🏳️‍🌈cure53@infosec.exchange
2025-10-09

@ll1t What is a last first responder? Like an "omgee sorry I am late, oh you already done? well, nice." kind of a thing? They teach that?

Cure53 🏳️‍🌈cure53@infosec.exchange
2025-10-09

@ll1t I'm not sure about liver, but in Mett, we're talking about three to four hedgehogs.

Cure53 🏳️‍🌈cure53@infosec.exchange
2025-10-09

@ll1t In recent years, thousands of European men have suffered from vegetarian shock, which can lead to the spontaneous loss of chest hair and worse. How dare you mock their misery!

Cure53 🏳️‍🌈cure53@infosec.exchange
2025-09-30

@alphaville Yes, we don't!

Cure53 🏳️‍🌈cure53@infosec.exchange
2025-09-30
Cure53 🏳️‍🌈cure53@infosec.exchange
2025-09-30

@alphaville Absolutely, full qDOM support including form node disentanglement is already available in PlatinumSanity Pro.

Cure53 🏳️‍🌈cure53@infosec.exchange
2025-09-30

@alphaville Running dompurify.exe as admin will auto-activate a free 30-day PlatinumSanity Pro subscription and enable our Platform AI features to boost your productivity.

So, yes. Of course. I guess. No?

Cure53 🏳️‍🌈cure53@infosec.exchange
2025-09-30

How do you like our new website we learned about just today?

dompurify.com/

Please make sure to run dompurify.exe on Windows 11 for best possible experience and Full HD.

Cure53 🏳️‍🌈 boosted:
2025-09-19

Intutively for a DOM Sanitizer configuration that looks like the following:

{
elements: ["div", "span"],
attributes: ["class"],
}

For a <div> element, which attributes do you think should/would be allowed?

(Boost appreciated)

Cure53 🏳️‍🌈cure53@infosec.exchange
2025-09-17

DOMPurify 3.2.7 has been released today, adding several fixes and improvements.

github.com/cure53/DOMPurify/re

Thanks to all folks who contributed 💕

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst