CVE-2026-103686
Deferred Deferred - Pending Action

DOM XSS in dom-sanitizer Library

Vulnerability report for CVE-2026-103686, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulDB

Description

A flaw has been found in rhukster dom-sanitizer up to 1.0.15. Impacted is the function DOMSanitizer::isDangerousUrl of the file src/DOMSanitizer.php of the component URL Validation. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 1.0.16 is recommended to address this issue. Patch name: 4623b565d060bc02ca5a07d8c8241fe28e2edfda. It is suggested to upgrade the affected component.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
rhukster dom-sanitizer to 1.0.15 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a cross-site scripting (XSS) flaw in the rhukster dom-sanitizer library up to version 1.0.15. The issue occurs in the DOMSanitizer::isDangerousUrl function, which fails to validate dangerous URL schemes like javascript: and data: in attributes other than href and xlink:href. This allows malicious scripts to bypass sanitization and execute when users interact with affected elements, such as form submissions.

Detection Guidance

To detect this vulnerability, check if your system uses rhukster dom-sanitizer version 1.0.15 or earlier. Run: grep -r "dom-sanitizer" /path/to/your/project/composer.lock or check the version in package.json. If using PHP, inspect installed packages with composer show rhukster/dom-sanitizer. Also review HTML forms or SVG content for javascript: or data: URIs in attributes like action, src, or poster.

Impact Analysis

This vulnerability enables attackers to inject malicious scripts into web pages via stored XSS. If exploited, it could allow attackers to steal user sessions, manipulate page content, or perform actions on behalf of users. The impact depends on the application's context and user privileges, but it poses a significant risk for data breaches or unauthorized actions.

Compliance Impact

This vulnerability could lead to unauthorized data access or manipulation, violating GDPR's integrity and confidentiality principles or HIPAA's security requirements for protected health information. Organizations using affected versions may face compliance violations, legal liabilities, and reputational damage if exploited.

Mitigation Strategies

Immediately upgrade rhukster dom-sanitizer to version 1.0.16 or later. Update your project dependencies using composer update rhukster/dom-sanitizer. If using a CMS like Grav, upgrade to the next release that includes this patched version. Review and sanitize any stored HTML or SVG content that may contain malicious URLs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103686. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart