CVE-2026-107380 — savg-sanitizer is a PHP SVG/XML sanitizer.
Description
savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer's isHrefSafeValue() validates an SVG href after XML DTD entity expansion, but saveXML() serializes the original entity reference after removing the DTD declaration. A crafted entity such as Tab can appear to the sanitizer as a safe fragment prefix while HTML5 Named Character Reference resolution during inline HTML rendering later converts the surviving reference to whitespace, exposing a javascript: URL. When an application embeds the sanitized SVG inline, a user who activates the link can cause script to execute in the embedding page's origin. This issue is fixed in version 1.0.0.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
Low
Privileges Required
UI
Required
User Interaction
S
Changed
Scope
C
Low
Confidentiality
I
Low
Integrity
A
None
Availability
References
- advisory[email protected]https://github.com/darylldoyle/svg-sanitizer/commit/23877db7e76f1e1df5c3e65ab30239219c3d2867
- advisory[email protected]https://github.com/darylldoyle/svg-sanitizer/releases/tag/1.0.0
- advisory[email protected]https://github.com/darylldoyle/svg-sanitizer/security/advisories/GHSA-9rjx-3jch-6vjf
Related threats
same CWE or vendorCVE-2026-84244 — IBM Guardium Data Protection 12.2 IBM Security Guardium Data Protection is vulnerable to stored cross-site scripting (XSS) in the Quick Search resu…
CVE-2026-84244 · 2h ago
CVE-2026-107393 — FreeScout is a self-hosted help desk and shared mailbox.
CVE-2026-107393 · 2h ago
CVE-2026-40804 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kodezen LLC aBlocks ablocks allows Reflected …
CVE-2026-40804 · 3h ago
CVE-2026-107303 — JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures.
CVE-2026-107303 · 4h ago
CVE-2026-104078 — Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute …
CVE-2026-104078 · 5h ago
CVE-2026-104077 — Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability that allows attackers to craft malicious Markdown notes exploiting in…
CVE-2026-104077 · 5h ago