PT-2026-108127 · Npm · Svg-Sanitizer
CVE-2026-107380
·
Published
2026-10-08
·
Updated
2026-10-09
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
enshrined/svg-sanitize versions prior to 1.0.0
Description
A logic error exists in the way SVG href values are validated. The
isHrefSafeValue() function validates the SVG href after XML DTD entity expansion, but the saveXML() function serializes the original entity reference while removing the DTD declaration. This creates a semantic mismatch between the sanitization process and how browsers render the SVG inline. An attacker can define a DTD entity that appears as a safe fragment prefix (starting with #) during sanitization but is resolved as a whitespace character (such as a Tab or NewLine) by HTML5 Named Character Reference resolution in the browser. This allows a javascript: URL to bypass the filter and execute arbitrary script in the embedding page's origin when a user activates the link.Recommendations
Update enshrined/svg-sanitize to version 1.0.0.
As a temporary mitigation, strip the DOCTYPE declaration from the SVG input before passing it to the sanitizer to eliminate entity definitions.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Svg-Sanitizer