{"id":"CVE-2026-107380","title":"savg-sanitizer is a PHP SVG/XML sanitizer","summary":"savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer's isHrefSafeValue() validates an SVG href after XML DTD entity expansion, but saveXML() serializes the original entity reference after removing the DTD declaration.…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"darylldoyle","product":"svg-sanitizer","affected":["svg-sanitizer < 1.0.0"],"patched":["enshrined/svg-sanitize 1.0.0"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:35:53.890","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107380","references":[{"url":"https://github.com/darylldoyle/svg-sanitizer/commit/23877db7e76f1e1df5c3e65ab30239219c3d2867","label":"security-advisories@github.com"},{"url":"https://github.com/darylldoyle/svg-sanitizer/releases/tag/1.0.0","label":"security-advisories@github.com"},{"url":"https://github.com/darylldoyle/svg-sanitizer/security/advisories/GHSA-9rjx-3jch-6vjf","label":"security-advisories@github.com"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107380"},{"url":"https://github.com/advisories/GHSA-9rjx-3jch-6vjf"}],"tags":["nvd","cve.org","ghsa","composer"],"aliases":["GHSA-9rjx-3jch-6vjf"],"ecosystem":"composer","ingestedAt":"2026-10-08T18:58:11.314Z","slug":"CVE-2026-107380","body":"## Overview\n\nsavg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer's isHrefSafeValue() validates an SVG href after XML DTD entity expansion, but saveXML() serializes the original entity reference after removing the DTD declaration. A crafted entity such as Tab can appear to the sanitizer as a safe fragment prefix while HTML5 Named Character Reference resolution during inline HTML rendering later converts the surviving reference to whitespace, exposing a javascript: URL. When an application embeds the sanitized SVG inline, a user who activates the link can cause script to execute in the embedding page's origin. This issue is fixed in version 1.0.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-107380)\n\nAffected packages:\n\n- `enshrined/svg-sanitize <= 0.22.0`\n\nPatched in:\n\n- `enshrined/svg-sanitize 1.0.0`\n\nSource: https://github.com/advisories/GHSA-9rjx-3jch-6vjf","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}