Description
savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer's isHrefSafeValue() validates an SVG href after XML DTD entity expansion, but saveXML() serializes the original entity reference after removing the DTD declaration. A crafted entity such as Tab can appear to the sanitizer as a safe fragment prefix while HTML5 Named Character Reference resolution during inline HTML rendering later converts the surviving reference to whitespace, exposing a javascript: URL. When an application embeds the sanitized SVG inline, a user who activates the link can cause script to execute in the embedding page's origin. This issue is fixed in version 1.0.0.
Published: 2026-10-08
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Stored XSS that permits execution of arbitrary JavaScript within the origin of the embedding page
Action: Patch Immediately
AI Analysis

Impact

savg‑sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg‑sanitizer’s isHrefSafeValue() validates an SVG href after XML DTD entity expansion, but saveXML() serializes the original entity reference after removing the DTD declaration. A crafted entity such as Tab can appear to the sanitizer as a safe fragment prefix while HTML5 Named Character Reference resolution during inline HTML rendering later converts the surviving reference to whitespace, exposing a javascript: URL. When an application embeds the sanitized SVG inline, a user who activates the link can cause script to execute in the embedding page’s origin. This issue is fixed in version 1.0.0.

Affected Systems

The flaw exists in the svg‑sanitizer library from the darylldoyle organization, in all releases before 1.0.0. Any application that uses the library to cleanse SVG or XML and then embeds the result inline in a web page is affected. No specific operating‑system or PHP‑version limitations were noted.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity for this client‑side XSS. The EPSS score is not available, so the current likelihood of exploitation cannot be quantified from public data. It is not listed in the CISA KEV catalog, suggesting no documented large‑scale exploits yet. The likely attack vector is client‑side; an attacker must supply a malicious SVG document that is later rendered inline by a user. If the victim interacts with a link inside the SVG, script execution occurs in the page’s origin. The exploitation requires the attacker to have a path to deliver or embed such SVG content, as well as the victim to view or activate the link.

Generated by OpenCVE AI on October 8, 2026 at 20:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade svg‑sanitizer to version 1.0.0 or later.
  • Implement a strict Content Security Policy that blocks inline scripts and disallows javascript: URLs in embedded SVG content.
  • Review all SVG inputs and reject any hrefs that reference external URLs or scripts before sanitization.

Generated by OpenCVE AI on October 8, 2026 at 20:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-9rjx-3jch-6vjf enshrined/svg-sanitize: Stored XSS via DTD Entity / HTML5 Named Character Reference Collision
History

Thu, 08 Oct 2026 18:15:00 +0000

Type Values Removed Values Added
Description savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer's isHrefSafeValue() validates an SVG href after XML DTD entity expansion, but saveXML() serializes the original entity reference after removing the DTD declaration. A crafted entity such as Tab can appear to the sanitizer as a safe fragment prefix while HTML5 Named Character Reference resolution during inline HTML rendering later converts the surviving reference to whitespace, exposing a javascript: URL. When an application embeds the sanitized SVG inline, a user who activates the link can cause script to execute in the embedding page's origin. This issue is fixed in version 1.0.0.
Title enshrined/svg-sanitize: Stored XSS via DTD Entity / HTML5 Named Character Reference Collision
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T18:06:14.107Z

Reserved: 2026-10-07T21:07:54.988Z

Link: CVE-2026-107380

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-08T18:17:23.787

Modified: 2026-10-08T21:35:53.890

Link: CVE-2026-107380

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T20:15:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')