Input validation error in SVG Sanitizer - #VU146562

 

Input validation error in SVG Sanitizer - #VU146562

Published: September 1, 2026


Vulnerability identifier: #VU146562
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to load external resources and disclose limited information.

The vulnerability exists due to improper handling of remote references in <image href> attributes in the SVG Sanitizer when sanitizing SVG content with remote reference removal enabled. A remote user can supply a crafted SVG containing a bare external href on an <image> element to load external resources and disclose limited information.

The issue occurs even when the removeRemoteReferences option is enabled, and it can be used for tracking pixel requests.


Affected software

SVG Sanitizer

Remediation

Install security update from vendor's website.

SVG Sanitizer - update to 1.0.0

External References

Related Security Bulletins