CVE-2026-103687
Received Received - Intake

Incomplete SVG Sanitization in dom-sanitizer

Vulnerability report for CVE-2026-103687, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulDB

Description

A vulnerability has been found in rhukster dom-sanitizer up to 1.0.15. The affected element is the function url of the file src/DOMSanitizer.php of the component SVG Sanitization. Such manipulation leads to incomplete blacklist. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.16 is sufficient to fix this issue. The name of the patch is 139c46c3d7c9bc81542b7b5a58d5cde5d0e0195a. Upgrading the affected component is recommended.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
rhukster dom-sanitizer to 1.0.16 (exc)
rhukster dom-sanitizer 1.0.16
rhukster dom-sanitizer to 1.0.15 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-184 The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.
CWE-183 The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are explicitly allowed by policy because the inputs are assumed to be safe, but the list is too permissive - that is, it allows an input that is unsafe, leading to resultant weaknesses.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-103687 is a vulnerability in the rhukster dom-sanitizer library up to version 1.0.15. It involves incomplete blacklisting in the SVG sanitization function, specifically in the url() handling of SVG presentation attributes like fill, stroke, and filter. Attackers can bypass URL validation using CSS comments or hex escapes, allowing external resource references to remain in sanitized output. The issue arises because the sanitizer does not normalize CSS before checking for external URLs in these attributes.

Detection Guidance

Check the installed version of dom-sanitizer using Composer: composer show rhukster/dom-sanitizer. If the version is below 1.0.16, the system is vulnerable. Inspect SVG files or HTML content processed by the library for attributes like fill, stroke, filter, clip-path, mask, or marker attributes containing url() values with obfuscated patterns such as comments or hex escapes.

Impact Analysis

This vulnerability could allow attackers to inject obfuscated external URLs into SVG content, leading to unintended HTTP requests when the sanitized SVG is rendered. This may result in IP and user-agent leakage, tracking, or potential data exfiltration. The impact is higher if untrusted SVG or HTML is embedded in applications, as it could enable stored cross-site scripting (XSS) via form submissions or external resource loads.

Compliance Impact

This vulnerability could lead to stored cross-site scripting (XSS) via SVG presentation attributes, potentially allowing unauthorized data access or modification. For GDPR, this may result in violations of data integrity and confidentiality requirements. For HIPAA, it could expose protected health information if sanitized SVG content is rendered in a healthcare application.

Mitigation Strategies

Upgrade the dom-sanitizer library to version 1.0.16 or later immediately. This can be done via Composer: composer require rhukster/dom-sanitizer:^1.0.16. Review and sanitize any SVG or HTML content processed by the library to ensure no malicious URLs are present in presentation attributes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103687. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart