CVE-2025-55166

MEDIUM

savg-sanitizer <0.22.0 - XSS

Title source: llm
STIX 2.1

Description

savg-sanitizer is a PHP SVG/XML sanitizer. Prior to version 0.22.0, the sanitization logic in the cleanXlinkHrefs method only searches for lower-case attribute name, which allows to by-pass the isHrefSafeValue check. As a result this allows cross-site scripting or linking to external domains. This issue has been patched in version 0.22.0.

Scores

CVSS v4 5.1
EPSS 0.0007
EPSS Percentile 21.6%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-601 CWE-79
Status published
Products (2)
darylldoyle/svg-sanitizer < 0.22.0
enshrined/svg-sanitize 0 - 0.22.0Packagist
Published Aug 12, 2025
Tracked Since Feb 18, 2026