Description
A flaw has been found in imgproxy up to 4.0.17. Affected by this vulnerability is the function sanitizeElement of the file processing/svg/svg.go of the component SVG Handler. Executing a manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-10-06
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting (XSS) via SVG sanitization flaw
Action: Patch Upgrade
AI Analysis

Impact

A flaw in the sanitizeElement function of imgproxy’s SVG handler allows an attacker to inject malicious script into the SVG processing pipeline, resulting in cross‑site scripting when the SVG is rendered. The vulnerability is classed as a moderate‑severity flaw with a CVSS score of 5.3 and a published exploit that can be delivered remotely through crafted SVG input. The injected code would execute in the context of the web application that serves the transformed image, potentially compromising user sessions or delivering further payloads.

Affected Systems

The issue affects the imgproxy project up to version 4.0.17. No other vendors or products are listed, and the API that processes SVG images is the primary entry point. All deployments using an impacted version are vulnerable until the fix is applied or the SVG feature is disabled.

Risk and Exploitability

The CVSS score indicates moderate impact; however the availability of a public exploit and the fact that the attack can be performed remotely raise the potential risk. With no EPSS score available, the likelihood of exploitation is uncertain, but the flaw is not present in the CISA KEV catalog. The vulnerability exploits a content‑sanitization weakness (CWE‑79) and a code injection point (CWE‑94), giving an attacker the opportunity to run arbitrary JavaScript in a client context.

Generated by OpenCVE AI on October 6, 2026 at 06:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade imgproxy to version 4.0.18 or later, which removes the sanitizeElement flaw.
  • If an upgrade is not immediately possible, disable SVG processing or reject all SVG uploads from untrusted sources.
  • Apply application‑level input validation to strip or reject disallowed SVG elements and attributes, or use an external sanitization library to filter SVG content before it reaches imgproxy.
  • Monitor image request logs for unusual parameters or repeated attempts to deliver SVG data that may indicate exploitation attempts.

Generated by OpenCVE AI on October 6, 2026 at 06:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 05:30:00 +0000

Type Values Removed Values Added
Description A flaw has been found in imgproxy up to 4.0.17. Affected by this vulnerability is the function sanitizeElement of the file processing/svg/svg.go of the component SVG Handler. Executing a manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title imgproxy SVG svg.go sanitizeElement cross site scripting
First Time appeared Imgproxy
Imgproxy imgproxy
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:imgproxy:imgproxy:*:*:*:*:*:*:*:*
Vendors & Products Imgproxy
Imgproxy imgproxy
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Imgproxy Imgproxy
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-06T05:15:15.121Z

Reserved: 2026-10-05T18:33:56.699Z

Link: CVE-2026-105708

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T06:17:00.030

Modified: 2026-10-06T06:17:00.030

Link: CVE-2026-105708

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T06:30:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')