Improper Neutralization of Alternate XSS Syntax in Kirby - #VU150664

 

Improper Neutralization of Alternate XSS Syntax in Kirby - #VU150664

Published: September 17, 2026


Vulnerability identifier: #VU150664
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-87
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script.

The vulnerability exists due to improper neutralization of alternate cross-site scripting syntax in Dom::sanitize() when sanitizing SVG or XML content for inline embedding. A remote user can submit crafted SVG or XML content for inline rendering to execute arbitrary script.

The rendered page must be viewed by another user.


Affected software

Kirby

Remediation

Install security update from vendor's website.

Kirby - addressed in versions 4.9.6, 5.6.0

External References

Related Security Bulletins