<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Dom-Sanitizer (&lt;= 1.0.15) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/dom-sanitizer--1.0.15/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 16:12:15 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/dom-sanitizer--1.0.15/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Incomplete Blacklist Vulnerability in rhukster dom-sanitizer</title><link>https://feed.craftedsignal.io/briefs/2026-10-dom-sanitizer-xss/</link><pubDate>Thu, 01 Oct 2026 16:12:15 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-dom-sanitizer-xss/</guid><description>The SVG Sanitization component in rhukster dom-sanitizer versions 1.0.15 and earlier contains an incomplete blacklist vulnerability in src/DOMSanitizer.php, allowing remote attackers to bypass security filters via malicious URL inputs.</description><content:encoded><![CDATA[<p>A security vulnerability identified as CVE-2026-103687 exists within the rhukster dom-sanitizer library, specifically affecting versions up to and including 1.0.15. The issue is located in the SVG Sanitization component, within the <code>url</code> function of <code>src/DOMSanitizer.php</code>. The vulnerability stems from an incomplete blacklist implementation, which allows remote attackers to supply specially crafted input that evades existing sanitization logic. This flaw can lead to cross-site scripting (XSS) or other injection-based attacks if the library is used to process untrusted user content. Exploitation can be performed remotely by submitting malicious payloads to applications utilizing the affected library. The maintainers have released a fix in version 1.0.16.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows remote attackers to bypass sanitization filters, potentially leading to unauthorized script execution in the context of the user's browser. This could be used to facilitate session hijacking, data theft, or other malicious actions within web applications relying on this library for SVG sanitization.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for development and security teams:</p>
<ul>
<li>Upgrade the rhukster dom-sanitizer library to version 1.0.16 or later to address CVE-2026-103687.</li>
<li>Review applications utilizing the library to ensure input processed by the SVG Sanitization component is validated against an updated security policy.</li>
<li>Perform code reviews on implementations using the <code>url</code> function within <code>src/DOMSanitizer.php</code> to identify any existing payloads leveraging the incomplete blacklist.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>