Description
savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer's isHrefSafeValue() validates an SVG href after XML DTD entity expansion, but saveXML() serializes the original entity reference after removing the DTD declaration. A crafted entity such as Tab can appear to the sanitizer as a safe fragment prefix while HTML5 Named Character Reference resolution during inline HTML rendering later converts the surviving reference to whitespace, exposing a javascript: URL. When an application embeds the sanitized SVG inline, a user who activates the link can cause script to execute in the embedding page's origin. This issue is fixed in version 1.0.0.
Related CPE's
Could not find any relations
References
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
5.4 · Medium
Information
Source identifier
Vulnerability status
Deferred
Published
2026-10-08T18:17:23.787Z
14 hours agoLast modified
2026-10-08T21:35:53.890Z
11 hours ago