
🟠 svg-sanitize, Cross-Site Scripting, #CVE-2026-107380 (Medium) -DC-Oct2026-2967 https://dailycve.com/svg-sanitize-cross-site-scripting-cve-2026-107380-medium-dc-oct2026-2967/
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer's isHrefSafeValue() validates an SVG href after XML DTD entity expansion, but saveXML() serializes the original entity reference after removing the DTD declaration. A crafted entity such as Tab can appear to the sanitizer as a safe fragment prefix while HTML5 Named Character Reference resolution during inline HTML rendering later converts the surviving reference to whitespace, exposing a javascript: URL. When an application embeds the sanitized SVG inline, a user who activates the link can cause script to execute in the embedding page's origin. This issue is fixed in version 1.0.0.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

🟠 svg-sanitize, Cross-Site Scripting, #CVE-2026-107380 (Medium) -DC-Oct2026-2967 https://dailycve.com/svg-sanitize-cross-site-scripting-cve-2026-107380-medium-dc-oct2026-2967/