Impact
A flaw in the sanitizeElement function of imgproxy’s SVG handler allows an attacker to inject malicious script into the SVG processing pipeline, resulting in cross‑site scripting when the SVG is rendered. The vulnerability is classed as a moderate‑severity flaw with a CVSS score of 5.3 and a published exploit that can be delivered remotely through crafted SVG input. The injected code would execute in the context of the web application that serves the transformed image, potentially compromising user sessions or delivering further payloads.
Affected Systems
The issue affects the imgproxy project up to version 4.0.17. No other vendors or products are listed, and the API that processes SVG images is the primary entry point. All deployments using an impacted version are vulnerable until the fix is applied or the SVG feature is disabled.
Risk and Exploitability
The CVSS score indicates moderate impact; however the availability of a public exploit and the fact that the attack can be performed remotely raise the potential risk. With no EPSS score available, the likelihood of exploitation is uncertain, but the flaw is not present in the CISA KEV catalog. The vulnerability exploits a content‑sanitization weakness (CWE‑79) and a code injection point (CWE‑94), giving an attacker the opportunity to run arbitrary JavaScript in a client context.
OpenCVE Enrichment