PT-2026-108127 · Npm · Svg-Sanitizer

CVE-2026-107380

·

Published

2026-10-08

·

Updated

2026-10-09

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions enshrined/svg-sanitize versions prior to 1.0.0
Description A logic error exists in the way SVG href values are validated. The isHrefSafeValue() function validates the SVG href after XML DTD entity expansion, but the saveXML() function serializes the original entity reference while removing the DTD declaration. This creates a semantic mismatch between the sanitization process and how browsers render the SVG inline. An attacker can define a DTD entity that appears as a safe fragment prefix (starting with #) during sanitization but is resolved as a whitespace character (such as a Tab or NewLine) by HTML5 Named Character Reference resolution in the browser. This allows a javascript: URL to bypass the filter and execute arbitrary script in the embedding page's origin when a user activates the link.
Recommendations Update enshrined/svg-sanitize to version 1.0.0. As a temporary mitigation, strip the DOCTYPE declaration from the SVG input before passing it to the sanitizer to eliminate entity definitions.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107380
GHSA-9RJX-3JCH-6VJF

Affected Products

Svg-Sanitizer