Impact
savg‑sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg‑sanitizer’s isHrefSafeValue() validates an SVG href after XML DTD entity expansion, but saveXML() serializes the original entity reference after removing the DTD declaration. A crafted entity such as Tab can appear to the sanitizer as a safe fragment prefix while HTML5 Named Character Reference resolution during inline HTML rendering later converts the surviving reference to whitespace, exposing a javascript: URL. When an application embeds the sanitized SVG inline, a user who activates the link can cause script to execute in the embedding page’s origin. This issue is fixed in version 1.0.0.
Affected Systems
The flaw exists in the svg‑sanitizer library from the darylldoyle organization, in all releases before 1.0.0. Any application that uses the library to cleanse SVG or XML and then embeds the result inline in a web page is affected. No specific operating‑system or PHP‑version limitations were noted.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity for this client‑side XSS. The EPSS score is not available, so the current likelihood of exploitation cannot be quantified from public data. It is not listed in the CISA KEV catalog, suggesting no documented large‑scale exploits yet. The likely attack vector is client‑side; an attacker must supply a malicious SVG document that is later rendered inline by a user. If the victim interacts with a link inside the SVG, script execution occurs in the page’s origin. The exploitation requires the attacker to have a path to deliver or embed such SVG content, as well as the victim to view or activate the link.
OpenCVE Enrichment
Github GHSA