PT-2025-32689 · Unknown · Svg-Sanitizer

Published

2025-08-12

·

Updated

2025-08-12

·

CVE-2025-55166

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: savg-sanitizer versions prior to 0.22.0
Description: savg-sanitizer is a PHP SVG/XML sanitizer. The sanitization logic in the cleanXlinkHrefs function only searches for lower-case attribute names, bypassing the isHrefSafeValue check. This allows for cross-site scripting or linking to external domains.
Recommendations: Update to savg-sanitizer version 0.22.0 or later.

Exploit

Fix

Open Redirect

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-55166
GHSA-22WQ-Q86M-83FH

Affected Products

Svg-Sanitizer