Description
savg-sanitizer is a PHP SVG/XML sanitizer. Prior to version 0.22.0, the sanitization logic in the cleanXlinkHrefs method only searches for lower-case attribute name, which allows to by-pass the isHrefSafeValue check. As a result this allows cross-site scripting or linking to external domains. This issue has been patched in version 0.22.0.
Scores
CVSS v4
5.1
EPSS
0.0007
EPSS Percentile
21.6%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-601
CWE-79
Status
published
Products (2)
darylldoyle/svg-sanitizer
< 0.22.0
enshrined/svg-sanitize
0 - 0.22.0Packagist
Published
Aug 12, 2025
Tracked Since
Feb 18, 2026