Spoofing attack in SVG Sanitizer - #VU146564
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote user to cause the victim to download attacker-controlled files.
The vulnerability exists due to improper neutralization of dangerous attributes in <a download> handling in the SVG Sanitizer when processing sanitized SVG content containing allowed download attributes and safe-listed data URIs. A remote user can craft an SVG link with an attacker-chosen filename and content source to cause the victim to download attacker-controlled files.
User interaction is required to open the downloaded file.