PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107380 darylldoyle CVE debrief

A vulnerability in the enshrined/svg-sanitize PHP library, known as svg-sanitizer, allows for stored XSS via DTD entity and HTML5 named character reference collision. The issue arises from the library's handling of SVG href attributes after XML DTD entity expansion and during inline HTML rendering. Specifically, the isHrefSafeValue() function validates an SVG href after XML DTD entity expansion, but saveXML() serializes the original entity reference after removing the DTD declaration. This can lead to a crafted entity being interpreted as a safe fragment prefix, which is later converted to whitespace during HTML5 Named Character Reference resolution, potentially exposing a javascript: URL. When an application embeds the sanitized SVG inline, a user activating the link can cause script to execute in the embedding page's origin.

Vendor
darylldoyle
Product
svg-sanitizer
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for applications using the svg-sanitizer library, especially those embedding sanitized SVGs inline, should assess exposure and prioritize updates to version 1.0.0 or later.

Why it matters

Defenders should care about CVE-2026-107380 because it allows for stored XSS in applications using svg-sanitizer versions prior to 1.0.0, potentially leading to script execution in embedding pages. Roles responsible for updating libraries and monitoring application security should assess exposure and prioritize remediation.

  • Script execution in embedding page's origin
  • Potential for user-activated link exploitation
  • Need for version verification and updates
  • Importance of monitoring link activations

Technical summary

The svg-sanitizer library, prior to version 1.0.0, does not properly handle SVG href attributes after XML DTD entity expansion and during inline HTML rendering. This can lead to stored XSS vulnerabilities when an application embeds sanitized SVGs inline. Specifically, the isHrefSafeValue() function validates an SVG href after XML DTD entity expansion, but saveXML() serializes the original entity reference after removing the DTD declaration. A crafted entity can appear to the sanitizer as a safe fragment prefix while HTML5 Named Character Reference resolution during inline HTML rendering later converts the surviving reference to whitespace, potentially exposing a javascript: URL.

Defensive priority

Defenders should prioritize updating the svg-sanitizer library to version 1.0.0 or later, and review applications that embed sanitized SVGs inline to assess exposure.

Recommended defensive actions

  • Update svg-sanitizer to version 1.0.0 or later
  • Review applications embedding sanitized SVGs inline to assess exposure
  • Monitor for suspicious link activations in embedding pages
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and source item provide details on the vulnerability, including its description, affected versions, and fixed version. However, the corpus does not establish versions beyond those provided, exploitation, impact, or remediation beyond updating to version 1.0.0 or later.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107380 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107380

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107380 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107380

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • enshrined/svg-sanitize: Stored XSS via DTD Entity / HTML5 Named Character Reference Collision

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107380.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/darylldoyle/svg-sanitizer/security/advisories/GHSA-9rjx-3jch-6vjf

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/darylldoyle/svg-sanitizer/commit/23877db7e76f1e1df5c3e65ab30239219c3d2867

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/darylldoyle/svg-sanitizer/releases/tag/1.0.0

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.