VDB
Sign up
HIGH7.5

GHSA-gf8j-v8x5-h9qp

XSS in enshrined/svg-sanitize due to mishandled script and data values in attributes

Quick fix

GHSA-gf8j-v8x5-h9qp — enshrined/svg-sanitize: upgrade to the fixed version with the command below.

composer require enshrined/svg-sanitize:^0.12.0

Details

enshrined/svg-sanitize before 0.12.0 mishandles script and data values in attributes, as demonstrated by unexpected whitespace such as in the javascript	:alert substring.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/enshrined/svg-sanitize
Introduced in: 0Fixed in: 0.12.0
Fixcomposer require enshrined/svg-sanitize:^0.12.0

References