Cross-site Scripting in enshrined/svg-sanitize
Moderate severity
GitHub Reviewed
Published
Feb 13, 2022
in
darylldoyle/svg-sanitizer
•
Updated Feb 5, 2024
Description
Published by the National Vulnerability Database
Feb 14, 2022
Published to the GitHub Advisory Database
Feb 14, 2022
Reviewed
Feb 14, 2022
Last updated
Feb 5, 2024
Impact
SVG sanitizer library before version
0.15.0
did not remove HTML elements wrapped in a CDATA section. As a result, SVG content embedded in HTML (fetched astext/html
) was susceptible to cross-site scripting. Plain SVG files (fetched asimage/svg+xml
) were not affected.Patches
This issue is fixed in
0.15.0
and higher.Workarounds
There is currently no workaround available without upgrading.
For more information
If you have any questions or comments about this advisory:
References