DOM/SVG/MathML Sanitizer Vulnerability in Rhukster's Product
CVE-2026-100370
4.7MEDIUM
What is CVE-2026-100370?
The DOM/SVG/MathML Sanitizer for PHP prior to version 1.0.15 has an incomplete input validation issue. Specifically, its isDangerousUrl() method inadequately rejects potentially dangerous URLs in href and xlink:href attributes. While it blocks the 'javascript:' scheme, it allows 'data:' URIs to pass through if they do not contain the substring 'onload'. This oversight lets malicious payloads, such as Base64-encoded scripts, evade detection, posing serious security risks. The issue has been resolved in version 1.0.15, making it crucial for users to update their software to this version or later.
Affected Version(s)
dom-sanitizer < 1.0.15
