Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-84371

Опубликовано: 01 сент. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting href or xlink:href gives the sibling values, from, to, or by attribute SVG SMIL URL semantics. In configurations that allow the animate, animateColor, animateMotion, animateTransform, or set elements, a values list can begin with a safe fragment and contain a later executable destination that survives allowedSchemesAppliedToAttributes checking. When the sanitized SVG is rendered, the browser can copy that later destination into the live link, and a victim who activates the link can execute script in the application's origin. This issue is fixed in version 2.17.7.

A flaw was found in sanitize-html. Improper validation of the animation value attributes in SVG files allows an attacker to bypass scheme filters and embed a malicious script destination within a list of values. When a user interacts with the rendered SVG animation, the embedded script executes in the context of the application, leading to Cross-Site Scripting (XSS).

Отчет

To exploit this flaw, an attacker needs to trick a user into clicking or interacting with a malicious rendered SVG file, reducing the likelihood of exploitation. Additionally, this vulnerability can only be triggered in configurations that allow the animate, animateColor, animateMotion, animateTransform or set elements. For these reasons, this issue has been rated with a moderate severity.

Меры по смягчению последствий

To mitigate this vulnerability, ensure the allowedTags configuration does not contain any of the following elements: animate, animateColor, animateMotion, animateTransform or set.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cost Management On Premisecostmanagement/costmanagement-ui-rhel10Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel9Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel9Fix deferred
Red Hat Enterprise Linux 10cockpit-image-builderFix deferred
Red Hat Hardened Imagesopentelemetry-collectorNot affected
Red Hat Hardened Imagesopentelemetry-collector-contribNot affected
Red Hat Hardened Imagesopentelemetry-collector-k8sNot affected
Red Hat Hardened Imagesprometheus3.13Not affected
Red Hat Hardened Imagesprometheus3.5Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mlflow-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2527092sanitize-html: stored XSS via SVG SMIL URI-list scheme-policy bypass

EPSS

Процентиль: 8%
0.00185
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
15 дней назад

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting href or xlink:href gives the sibling values, from, to, or by attribute SVG SMIL URL semantics. In configurations that allow the animate, animateColor, animateMotion, animateTransform, or set elements, a values list can begin with a safe fragment and contain a later executable destination that survives allowedSchemesAppliedToAttributes checking. When the sanitized SVG is rendered, the browser can copy that later destination into the live link, and a victim who activates the link can execute script in the application's origin. This issue is fixed in version 2.17.7.

CVSS3: 5.4
github
15 дней назад

ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass

EPSS

Процентиль: 8%
0.00185
Низкий

5.4 Medium

CVSS3

Уязвимость CVE-2026-84371