
Yuji Kiba
[HackerNotes Ep.111] How to Bypass DOMPurify with Kévin Mizu
In this episode Justin interviews Kévin Mizu to showcase his knowledge regarding DOMPurify and its misconfigurations. We walk through some of Kevin’s research, highlighting things like Dangerous allow-lists and URI Attributes, DOMPurify hooks, node manipulation, and DOM Clobbering.

Yuji Kiba