CVE-2026-84371Medium· 5.4▾ SunlitApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 2.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting href or xlink:href gives the sibling values, from, to, or by attribute SVG SMIL URL semantics. In configurations that allow the animate, animateColor, animateMotion, animateTransform, or set elements, a values list can begin with a safe fragment and contain a later executable destination that survives allowedSchemesAppliedToAttributes checking. When the sanitized SVG is rendered, the browser can copy that later destination into the live link, and a victim who activates the link can execute script in the application's origin. This issue is fixed in version 2.17.7.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
sanitize-html >= 1.9.0, <= 2.17.6Patched in:
sanitize-html 2.17.7Source: https://github.com/advisories/GHSA-g8qq-57p8-ggw5
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-93432Medium· 6.1A flaw was found in the Quarkus Qute template engine
CVE-2024-23176Medium· 5.4An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2
CVE-2026-87933High· 8.6cJSON: cJSON: Memory corruption via use after free in cJSONUtils_MergePatch (CVE-2026-87933)
CVE-2023-54354Medium· 5.9Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2026-54516Medium· 5.3jackson-databind: jackson-databind: Security bypass due to improper handling of renamed properties (CVE-2026-54516)
CVE-2026-80110High· 8.1A flaw was found in pki-core