Junglewise Threat Intelligence

CVE-2023-40013: external-svg-loader Cross-site Scripting in sanitization

CVE-2023-40013 · Severity: low · CVSS 3.1 · Published 2023-08-14

Vendors: npm.

Executive brief

external-svg-loader is a JavaScript library used to safely load and inject SVG files into web pages. The library's input sanitization logic incompletely filters dangerous event handlers from SVG code, allowing attackers to craft malicious SVG files with unfiltered event attributes like onbegin that execute arbitrary JavaScript when loaded. This enables stored XSS attacks on any website permitting users to provide or upload SVG files.

Technical details

external-svg-loader uses a blocklist approach to strip event attributes from SVG input, but the list is incomplete and misses numerous SVG event handlers including onbegin, onend, onstart, onfocusin, onfocusout, onshow, and others. An attacker can bypass sanitization by using attributes not in the blocklist—for example, the onbegin attribute on an SVG animate element—to execute arbitrary JavaScript without requiring the data-js="enabled" flag. The vulnerability has a network attack vector with no authentication or user interaction required. A fix was released in version 1.6.9; affected versions are 1.6.8 and earlier.

Affected products

  • npm external-svg-loader <=1.6.8

Timeline

  • 2023-08-14: disclosed
  • 2023-08-14: patched: Fixed in version 1.6.9

References