Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-93vf-569f-22cq | rhukster/dom-sanitizer: SVG <style> tag allows CSS injection via unfiltered url() and @import directives |
Mon, 20 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rhukster
Rhukster dom-sanitizer |
|
| Vendors & Products |
Rhukster
Rhukster dom-sanitizer |
|
| Metrics |
ssvc
|
Fri, 17 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows <style> elements in SVG content but never inspects their text content. CSS url() references and @import rules pass through unfiltered, causing the browser to issue HTTP requests to attacker-controlled hosts when the sanitized SVG is rendered. Version 1.0.10 fixes the issue. | |
| Title | rhukster/dom-sanitizer: SVG <style> tag allows CSS injection via unfiltered url() and @import directives | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-20T14:57:39.192Z
Reserved: 2026-04-10T20:22:44.036Z
Link: CVE-2026-40301
Updated: 2026-04-20T14:42:32.819Z
Status : Deferred
Published: 2026-04-17T21:16:34.850
Modified: 2026-04-29T21:04:10.060
Link: CVE-2026-40301
No data.
OpenCVE Enrichment
Updated: 2026-04-20T14:59:36Z
Github GHSA