Executive brief
@mattkrick/sanitize-svg is a JavaScript library used to remove potentially dangerous code from SVG (Scalable Vector Graphics) files. The library's filter for blocking XSS attacks has gaps that allow attackers to embed malicious JavaScript through anchor tags and foreign object tags. Applications using this library to sanitize untrusted SVG files may be vulnerable to account takeover, credential theft, or malware injection when users view or interact with the malicious SVGs.
Technical details
The vulnerability is a Cross-Site Scripting (CWE-79) filter bypass in a deny-list-based SVG sanitization library. The sanitizer only blocks literal <script> tags and on* event handlers, but fails to neutralize other JavaScript injection vectors such as href="javascript:" in anchor tags and foreignObject/iframe elements. No authentication or special privileges are required to exploit this; however, user interaction (clicking a link) or browser context (foreignObject execution) is needed depending on the attack vector. An attacker can craft malicious SVGs that, when processed and rendered by downstream applications, execute arbitrary JavaScript in the user's browser with access to session cookies and sensitive data. The vulnerability was patched in version 0.4.0.
Affected products
- mattkrick sanitize-svg <= 0.3.1
Timeline
- 2023-01-04: disclosed
- 2023-01-05: patched: Version 0.4.0