Vulnerability GHSA-8rc5-hx3v-2jg7
Medium Risk
MEDIUM RISK
CVSS Score: 6.1
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
6 years ago
February 27, 2020 at 08:36 PM UTC
Sanitizer bypass in svg-sanitizer
0.1.0 - 0.5.3 and 0.5.3.1 - 0.13.0
0.1.0 - 0.5.3 and 0.5.3.1 - 0.13.0
Summary
Sanitizer bypass in svg-sanitizer
Details
It is possible to bypass enshrined/svg-sanitize before 0.13.1 using the "xlink:href" attribute due to mishandling of the xlink namespace by the sanitizer.
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
4 hours ago
enshrined/svg-sanitize: Stored XSS via DTD Entity / HTML5 Named Character Reference Collision
0.1.0 - 0.5.3 and 0.5.3.1 - 0.22.0 GHSA-9rjx-3jch-6vjf
0.1.0 - 0.5.3 and 0.5.3.1 - 0.22.0 GHSA-9rjx-3jch-6vjf
Medium Risk
4 hours ago
svg-sanitizer: Mixed-case xlink:HrEf skips the `<use>` nesting-DoS check in Resolver::processReferences
0.1.0 - 0.5.3 and 0.5.3.1 - 0.22.0 GHSA-m9xh-6747-9r6f
0.1.0 - 0.5.3 and 0.5.3.1 - 0.22.0 GHSA-m9xh-6747-9r6f
Medium Risk
4 hours ago
enshrined/svg-sanitize: Denial of Service via DTD Attribute Declaration Crash
0.1.0 - 0.5.3 and 0.5.3.1 - 0.22.0 GHSA-v383-3rw5-q8rf
0.1.0 - 0.5.3 and 0.5.3.1 - 0.22.0 GHSA-v383-3rw5-q8rf
Medium Risk
1 year ago
svg-sanitizer Bypasses Attribute Sanitization
0.1.0 - 0.5.3 and 0.5.3.1 - 0.21.0 GHSA-22wq-q86m-83fh
0.1.0 - 0.5.3 and 0.5.3.1 - 0.21.0 GHSA-22wq-q86m-83fh
Medium Risk
4 years ago
Cross-site Scripting in enshrined/svg-sanitize
0.1.0 - 0.5.3 and 0.5.3.1 - 0.14.1 GHSA-fqx8-v33p-4qcc
0.1.0 - 0.5.3 and 0.5.3.1 - 0.14.1 GHSA-fqx8-v33p-4qcc
Impacted packages
Timeline
Published
6 years ago
February 27, 2020 at 08:36 PM UTC
Fixed (0.13.1)
6 years ago
December 09, 2019 at 08:43 AM UTC
Last Modified
28 days ago
September 10, 2026 at 03:49 AM UTC