DOM/SVG/MathML Sanitizer Vulnerability in Rhukster's Product
CVE-2026-100370

4.7MEDIUM

Key Information:

Vendor

Rhukster

Vendor
CVE Published:
28 September 2026

What is CVE-2026-100370?

The DOM/SVG/MathML Sanitizer for PHP prior to version 1.0.15 has an incomplete input validation issue. Specifically, its isDangerousUrl() method inadequately rejects potentially dangerous URLs in href and xlink:href attributes. While it blocks the 'javascript:' scheme, it allows 'data:' URIs to pass through if they do not contain the substring 'onload'. This oversight lets malicious payloads, such as Base64-encoded scripts, evade detection, posing serious security risks. The issue has been resolved in version 1.0.15, making it crucial for users to update their software to this version or later.

Affected Version(s)

dom-sanitizer < 1.0.15

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.