Low · 3.0 PHP packages GHSA-9rjx-3jch-6vjf CVE-2026-107380 PKSA-8j6w-3kr7-s9xk
CVE-2026-107380: Stored XSS in enshrined/svg-sanitize via DTD entity / HTML5 named character reference collision
A stored XSS issue in enshrined/svg-sanitize allows a crafted DTD entity to bypass href validation and survive serialization, enabling a javascript: URL when the sanitized SVG is embedded inline. The issue is fixed in 1.0.0. (Sources: GHSA, OSV, NVD)
AI summary
enshrined/svg-sanitize (PHP) contains a vulnerability (CVE-2026-107380 / GHSA-9rjx-3jch-6vjf) where a crafted XML DTD entity can cause an href to appear safe to the sanitizer but be converted to a javascript: URL when the sanitized SVG is rendered inline. The vendor released a fix in 1.0.0. [Sources: 3976, 4174, 8433, 31854]
What happened
savg-sanitizer (enshrined/svg-sanitize) validates an SVG href after XML DTD entity expansion, but saveXML() then serializes the original entity reference after the DTD declaration is removed. A crafted entity (for example a Tab entity) can appear to the sanitizer as a safe fragment prefix, while later HTML5 Named Character Reference resolution during inline HTML rendering converts the surviving reference to whitespace and exposes a javascript: URL. When an application embeds the sanitized SVG inline, activating the link can execute script in the embedding page's origin. The issue is fixed in version 1.0.0. [Sources: 3976, 4174, 8433, 31854]
Technical cause
The sanitizer's isHrefSafeValue() check runs after XML DTD entity expansion, but saveXML() outputs the original entity reference once the DTD is removed. That mismatch allows a crafted entity to pass validation yet later be interpreted (via HTML5 Named Character Reference resolution) in a way that exposes a javascript: URL when rendered inline. This is an input neutralization failure that leads to cross-site scripting. [Sources: 3976, 4174, 8433, 31854]
Why it matters
If an application sanitizes SVG input with this library and then embeds the sanitized SVG inline in a page, an attacker who supplies a crafted SVG can create a link that appears safe to the sanitizer but executes script in the page's origin when followed. This can lead to cross-site scripting in the embedding site. [Sources: 3976, 4174, 8433, 31854]
Who is affected
Projects and applications that use enshrined/svg-sanitize to sanitize SVG input and that embed the sanitized SVG inline in HTML pages are affected. The advisory indicates the issue exists in earlier releases and is fixed in the vendor update 1.0.0. [Sources: 3976, 4174, 8433, 31854]
Discovery and timeline
Public advisories and vulnerability databases published details on 2026-10-08 (OSV / GitHub advisory sources) and NVD lists the entry with a 2026-10-08 publication timestamp. The vendor fix is listed as 1.0.0 in the advisories. The sources do not provide additional public disclosure or exploit timeline information. [Sources: 3976, 4174, 8433, 31854]
Affected versions
Advisories indicate the problem exists in releases prior to the vendor fix and specifically reference releases up to 0.22.0 in some source expressions; the vendor fix is 1.0.0. For remediation, treat any installed release earlier than 1.0.0 (including those up to 0.22.0 as cited) as potentially vulnerable. [Sources: 3976, 4174, 8433, 31854]
Fixes and mitigation
A vendor update is available; the advisories list a fixed version of 1.0.0. Applying the vendor update to 1.0.0 is the primary remediation. The advisories do not list alternative mitigations. [Sources: 3976, 4174, 8433, 31854]
Recommended action
Update enshrined/svg-sanitize to 1.0.0. If you cannot update immediately, avoid embedding user-supplied SVG inline in HTML pages or apply server-side measures to prevent DTD processing and entity expansion before sanitization. Confirm the update in your dependency lockfiles and rebuild deployments. [Sources: 3976, 4174, 8433, 31854]
PatchBriefing score
3.0 / 10 · Low
Official CVSS: 5.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Why this score
The advisory lists a CVSS v3.1 base score of 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N). That score reflects network attack vector, low attack complexity, required low privileges and user interaction, and partial impact to confidentiality and integrity with scope change. Patchwire score is 3; the published score factors attribute 2.97 points to the CVSS base (5.4) and show no additional contribution from known exploitation, public exploit, or EPS S indicators. [Sources: 3976, 4174, 8433, 31854]
Affected versions
- enshrined/svg-sanitize ≥ 0 < 1.0.0
- vulnerable
- enshrined/svg-sanitize
- vulnerable
- enshrined/svg-sanitize <=0.22.0
- vulnerable
- enshrined/svg-sanitize <= 0.22.0
- vulnerable
- ≥ 1.0.0
- patched
Reported fixes
A vendor update is available; the advisories list a fixed version of 1.0.0. Applying the vendor update to 1.0.0 is the primary remediation. The advisories do not list alternative mitigations. [Sources: 3976, 4174, 8433, 31854]
How this was built
4 source records were collected, matched and used to prepare the report above.
-
OSV.dev database
-
Packagist Security Advisories registry
-
GitHub Advisory Database database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email