Vulnerability GHSA-8rc5-hx3v-2jg7

Medium Risk
MEDIUM RISK
CVSS Score: 6.1
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
6 years ago
February 27, 2020 at 08:36 PM UTC
Sanitizer bypass in svg-sanitizer
0.1.0 - 0.5.3 and 0.5.3.1 - 0.13.0
0.1.0 - 0.5.3 and 0.5.3.1 - 0.13.0

Summary

Sanitizer bypass in svg-sanitizer

Details

It is possible to bypass enshrined/svg-sanitize before 0.13.1 using the "xlink:href" attribute due to mishandling of the xlink namespace by the sanitizer.

Impacted packages

Timeline

Published
6 years ago
February 27, 2020 at 08:36 PM UTC
Fixed (0.13.1)
6 years ago
December 09, 2019 at 08:43 AM UTC
Last Modified
28 days ago
September 10, 2026 at 03:49 AM UTC