VDB
Sign up
MEDIUM6.2

GHSA-fqx8-v33p-4qcc

Cross-site Scripting in enshrined/svg-sanitize

Quick fix

GHSA-fqx8-v33p-4qcc — enshrined/svg-sanitize: upgrade to the fixed version with the command below.

composer require enshrined/svg-sanitize:^0.15.0

Details

### Impact SVG sanitizer library before version `0.15.0` did not remove HTML elements wrapped in a CDATA section. As a result, SVG content embedded in HTML (fetched as `text/html`) was susceptible to cross-site scripting. Plain SVG files (fetched as `image/svg+xml`) were not affected.

### Patches This issue is fixed in `0.15.0` and higher.

### Workarounds There is currently no workaround available without upgrading.

### For more information If you have any questions or comments about this advisory: * Open an issue in [Github](https://github.com/darylldoyle/svg-sanitizer/issues) * Email us at [daryll@enshrined.co.uk](mailto:daryll@enshrined.co.uk)

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/enshrined/svg-sanitize
Introduced in: 0Fixed in: 0.15.0
Fixcomposer require enshrined/svg-sanitize:^0.15.0

References