rhukster/dom-sanitizer is vulnerable to Cross-Site Scripting (XSS)
61
Medium Risk
dom-sanitizer lets animateTransform, animateColor, and animateMotion elements pass its SVG/HTML allow-list without checking their attributeName target. On Safari/WebKit, attributeName can target href, so the animation recreates a javascript: URL on an anchor even after the static href value was stripped. Activating the animated link executes attacker-controlled JavaScript in the victim's browser. The fix rejects animation elements whose target attribute is a URL, event-handler, style, or namespace attribute.
You are affected if you are using a version that falls within the vulnerable range and you render the sanitized SVG in Safari or WebKit, where animateTransform can retarget the href attribute.
rhukster/dom-sanitizer is vulnerable to Cross-Site Scripting (XSS) in versions 1.0.0 - 1.0.16.
Upgrade the rhukster/dom-sanitizer library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.