CVE-2026-103687

Summary

A vulnerability has been found in rhukster dom-sanitizer up to 1.0.15. The affected element is the function url of the file src/DOMSanitizer.php of the component SVG Sanitization. Such manipulation leads to incomplete blacklist. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.16 is sufficient to fix this issue. The name of the patch is 139c46c3d7c9bc81542b7b5a58d5cde5d0e0195a. Upgrading the affected component is recommended.

Affected Software

VendorProductVersion RangeStatus
rhuksterdom-sanitizer1.0.0affected
rhuksterdom-sanitizer1.0.1affected
rhuksterdom-sanitizer1.0.2affected
rhuksterdom-sanitizer1.0.3affected
rhuksterdom-sanitizer1.0.4affected
rhuksterdom-sanitizer1.0.5affected
rhuksterdom-sanitizer1.0.6affected
rhuksterdom-sanitizer1.0.7affected
rhuksterdom-sanitizer1.0.8affected
rhuksterdom-sanitizer1.0.9affected
rhuksterdom-sanitizer1.0.10affected
rhuksterdom-sanitizer1.0.11affected
rhuksterdom-sanitizer1.0.12affected
rhuksterdom-sanitizer1.0.13affected
rhuksterdom-sanitizer1.0.14affected
rhuksterdom-sanitizer1.0.15affected
rhuksterdom-sanitizer1.0.16unaffected

Weaknesses

  • CWE-184: Incomplete Blacklist
  • CWE-183: Permissive List of Allowed Inputs

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: yes
    • Technical Impact: partial

References