VDB
Sign up
MEDIUM6.1

GHSA-8rc5-hx3v-2jg7

Sanitizer bypass in svg-sanitizer

Quick fix

GHSA-8rc5-hx3v-2jg7 — enshrined/svg-sanitize: upgrade to the fixed version with the command below.

composer require enshrined/svg-sanitize:^0.13.1

Details

It is possible to bypass enshrined/svg-sanitize before 0.13.1 using the "xlink:href" attribute due to mishandling of the xlink namespace by the sanitizer.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/enshrined/svg-sanitize
Introduced in: 0Fixed in: 0.13.1
Fixcomposer require enshrined/svg-sanitize:^0.13.1

References