Bug 2527092 (CVE-2026-84371)

Summary: CVE-2026-84371 sanitize-html: stored XSS via SVG SMIL URI-list scheme-policy bypass
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: akhatavk, anthomas, aos-team-art-private, aruklets, asdas, cmyers, dnakabaa, doconnor, dpaolell, ehelms, ggainey, gparvin, jdelft, jpasqual, jupierce, juwatts, kaycoth, kshier, lcouzens, lgarciaa, mbiarnes, mdellweg, mhulan, nmoumoul, osousa, pcreech, ppalepu, ppostler, prdhamdh, prwatson, rchan, rhaigner, rhel-process-autobot, sdawley, sghai, sidsharm, smallamp, stcannon, suppawar, teagle, tmalecek, vlaad, watson-tool-maintainers, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in sanitize-html. Improper validation of the animation value attributes in SVG files allows an attacker to bypass scheme filters and embed a malicious script destination within a list of values. When a user interacts with the rendered SVG animation, the embedded script executes in the context of the application, leading to Cross-Site Scripting (XSS).
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2527486, 2527487, 2527488, 2527489, 2527491, 2527495, 2527496, 2527498, 2527499, 2527500, 2527503, 2527504, 2527506, 2527508, 2527509, 2527511    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-01 21:02:01 UTC
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting href or xlink:href gives the sibling values, from, to, or by attribute SVG SMIL URL semantics. In configurations that allow the animate, animateColor, animateMotion, animateTransform, or set elements, a values list can begin with a safe fragment and contain a later executable destination that survives allowedSchemesAppliedToAttributes checking. When the sanitized SVG is rendered, the browser can copy that later destination into the live link, and a victim who activates the link can execute script in the application's origin. This issue is fixed in version 2.17.7.