enshrined/svg-sanitize is vulnerable to Information Exposure
35
Low Risk
With removeRemoteReferences(true) enabled, several remote references slip past the filter: <style> element text is never inspected, bare remote href/src values and unquoted url(...) references are not matched, and CSS escapes hide @import/url() tokens. An embedded SVG can therefore load external resources or exfiltrate host-page data character by character through injected CSS. The fix inspects <style> text and style attributes, resolves CSS escapes and comments before matching, and detects bare, unquoted, and image-set() remote references.
You are affected if you are using a version that falls within the vulnerable range and you embed the sanitized SVG inline in an HTML page with remote-reference removal enabled.
enshrined/svg-sanitize is vulnerable to Information Exposure in versions 0.0.1 - 0.22.0.
Upgrade the enshrined/svg-sanitize library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.