CVE-2023-22461 Information
Jan 05, 2023
cve
Description
The sanitize-svg package a small SVG sanitizer to prevent cross-site scripting attacks uses a deny-list-pattern to sanitize SVGs to prevent XSS. In doing so literal <script>-tags and on-event handlers were detected in versions prior to 0.4.0. As a result downstream software that relies on sanitize-svg and expects resulting SVGs to be safe may be vulnerable to cross-site scripting. This vulnerability was addressed in v0.4.0. There are no known workarounds
Reference
https://github.com/mattkrick/sanitize-svg/security/advisories/GHSA-h857-2g56-468g https://github.com/mattkrick/sanitize-svg/commit/b107e453ede7b58adcccae74a3e474c012eec85d
Share on: