MEDIUM6.1
GHSA-8rc5-hx3v-2jg7
Sanitizer bypass in svg-sanitizer
Quick fix
GHSA-8rc5-hx3v-2jg7 — enshrined/svg-sanitize: upgrade to the fixed version with the command below.
composer require enshrined/svg-sanitize:^0.13.1Details
It is possible to bypass enshrined/svg-sanitize before 0.13.1 using the "xlink:href" attribute due to mishandling of the xlink namespace by the sanitizer.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/enshrined/svg-sanitize
Introduced in:
0Fixed in: 0.13.1Fix
composer require enshrined/svg-sanitize:^0.13.1