CVE-2026-107380
Received Received - Intake

Stored XSS in SVG via javascript: URL in savg-sanitizer

Vulnerability report for CVE-2026-107380, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer's isHrefSafeValue() validates an SVG href after XML DTD entity expansion, but saveXML() serializes the original entity reference after removing the DTD declaration. A crafted entity such as Tab can appear to the sanitizer as a safe fragment prefix while HTML5 Named Character Reference resolution during inline HTML rendering later converts the surviving reference to whitespace, exposing a javascript: URL. When an application embeds the sanitized SVG inline, a user who activates the link can cause script to execute in the embedding page's origin. This issue is fixed in version 1.0.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
darylldoyle svg-sanitizer < 1.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored Cross-Site Scripting (XSS) vulnerability in the svg-sanitizer library affecting versions up to 0.22.0. It occurs due to a mismatch between XML entity resolution during sanitization and HTML5 Named Character Reference resolution in browsers. An attacker crafts an SVG file with a DTD entity that collides with an HTML5 Named Character Reference (e.g., &Tab;), bypassing href validation. The sanitizer incorrectly treats the href as safe during validation, while the browser resolves it as a tab character, allowing a javascript: URL to execute when the SVG is rendered inline in HTML.

Detection Guidance

Check installed versions of svg-sanitizer with composer show darylldoyle/svg-sanitizer. Inspect SVG files for DOCTYPE/DTD declarations or entities like &Tab;. Use grep to search for href attributes with javascript: URLs in sanitized SVGs.

Impact Analysis

This vulnerability can lead to account takeover or session hijacking if exploited. It requires user interaction, such as clicking a malicious link, but can expose users to script execution in the embedding page's origin when an SVG is embedded inline. The impact includes potential theft of sensitive data or unauthorized actions on behalf of the user.

Mitigation Strategies

Upgrade svg-sanitizer to version 1.0.0 or later. Strip DOCTYPE/DTD declarations before parsing SVGs. Validate hrefs after serialization and expand entities before validation. Monitor for suspicious SVG uploads or inline embeds.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107380. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart