Back to database
Schedule54Medium5.4VulnerabilityCVE-2026-107380No patch link observed

CVE-2026-107380 — savg-sanitizer is a PHP SVG/XML sanitizer.

Published Oct 8, 2026, 06:17 PM UTCIngested 4h agoSource NVD(cve-db)CVE-2026-107380

Description

savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer's isHrefSafeValue() validates an SVG href after XML DTD entity expansion, but saveXML() serializes the original entity reference after removing the DTD declaration. A crafted entity such as Tab can appear to the sanitizer as a safe fragment prefix while HTML5 Named Character Reference resolution during inline HTML rendering later converts the surviving reference to whitespace, exposing a javascript: URL. When an application embeds the sanitized SVG inline, a user who activates the link can cause script to execute in the embedding page's origin. This issue is fixed in version 1.0.0.

CVSS v3.1 base metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
5.4

Medium severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

Low

Attack Complexity

PR

Low

Privileges Required

UI

Required

User Interaction

S

Changed

Scope

C

Low

Confidentiality

I

Low

Integrity

A

None

Availability