PatchSiren cyber security CVE debrief
CVE-2026-107380 darylldoyle CVE debrief
A vulnerability in the enshrined/svg-sanitize PHP library, known as svg-sanitizer, allows for stored XSS via DTD entity and HTML5 named character reference collision. The issue arises from the library's handling of SVG href attributes after XML DTD entity expansion and during inline HTML rendering. Specifically, the isHrefSafeValue() function validates an SVG href after XML DTD entity expansion, but saveXML() serializes the original entity reference after removing the DTD declaration. This can lead to a crafted entity being interpreted as a safe fragment prefix, which is later converted to whitespace during HTML5 Named Character Reference resolution, potentially exposing a javascript: URL. When an application embeds the sanitized SVG inline, a user activating the link can cause script to execute in the embedding page's origin.
- Vendor
- darylldoyle
- Product
- svg-sanitizer
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for applications using the svg-sanitizer library, especially those embedding sanitized SVGs inline, should assess exposure and prioritize updates to version 1.0.0 or later.
Why it matters
Defenders should care about CVE-2026-107380 because it allows for stored XSS in applications using svg-sanitizer versions prior to 1.0.0, potentially leading to script execution in embedding pages. Roles responsible for updating libraries and monitoring application security should assess exposure and prioritize remediation.
- Script execution in embedding page's origin
- Potential for user-activated link exploitation
- Need for version verification and updates
- Importance of monitoring link activations
Technical summary
The svg-sanitizer library, prior to version 1.0.0, does not properly handle SVG href attributes after XML DTD entity expansion and during inline HTML rendering. This can lead to stored XSS vulnerabilities when an application embeds sanitized SVGs inline. Specifically, the isHrefSafeValue() function validates an SVG href after XML DTD entity expansion, but saveXML() serializes the original entity reference after removing the DTD declaration. A crafted entity can appear to the sanitizer as a safe fragment prefix while HTML5 Named Character Reference resolution during inline HTML rendering later converts the surviving reference to whitespace, potentially exposing a javascript: URL.
Defensive priority
Defenders should prioritize updating the svg-sanitizer library to version 1.0.0 or later, and review applications that embed sanitized SVGs inline to assess exposure.
Recommended defensive actions
- Update svg-sanitizer to version 1.0.0 or later
- Review applications embedding sanitized SVGs inline to assess exposure
- Monitor for suspicious link activations in embedding pages
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description, affected versions, and fixed version. However, the corpus does not establish versions beyond those provided, exploitation, impact, or remediation beyond updating to version 1.0.0 or later.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107380 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107380
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107380 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107380
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
enshrined/svg-sanitize: Stored XSS via DTD Entity / HTML5 Named Character Reference Collision
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107380.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/darylldoyle/svg-sanitizer/security/advisories/GHSA-9rjx-3jch-6vjf
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/darylldoyle/svg-sanitizer/commit/23877db7e76f1e1df5c3e65ab30239219c3d2867
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/darylldoyle/svg-sanitizer/releases/tag/1.0.0
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.