{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/svgo-3.x--3.3.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:svgo_project:svgo:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-84370"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["svgo (2.x \u003c 2.8.4)","svgo (3.x \u003c 3.3.5)","svgo (4.x \u003c 4.1.0)"],"_cs_severities":["high"],"_cs_tags":["xss","svg","sanitization-bypass","cve-2026-84370"],"_cs_type":"advisory","_cs_vendors":["SVGO"],"content_html":"\u003cp\u003eSVGO (SVG Optimizer) contains a security flaw in its \u003ccode\u003eremoveScripts\u003c/code\u003e plugin, identified as CVE-2026-84370. The plugin, intended to strip executable script elements and links from SVG files, fails to adequately neutralize malicious payloads due to two specific bypass mechanisms. First, the plugin only validates unprefixed \u003ccode\u003e\u0026lt;a\u0026gt;\u003c/code\u003e tags and ignores namespace-prefixed anchors (e.g., \u003ccode\u003e\u0026lt;svg:a\u0026gt;\u003c/code\u003e), allowing executable links to persist. Second, the URL scheme validator does not sanitize embedded ASCII control characters such as tabs, line feeds, or carriage returns. Browsers ignore these characters during URI parsing, effectively allowing attackers to obfuscate \u003ccode\u003ejavascript:\u003c/code\u003e URI schemes (e.g., \u003ccode\u003ejava\u0026amp;#9;script:\u003c/code\u003e) to bypass the plugin's pattern matching.\u003c/p\u003e\n\u003cp\u003eThis vulnerability affects versions of the \u003ccode\u003esvgo\u003c/code\u003e npm package across major release lines. Users relying on this plugin as the sole sanitization mechanism for untrusted user-provided SVG files are at risk of cross-site scripting (XSS) if the optimized output is rendered in an active browser context.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation occurs when an application processes untrusted, attacker-controlled SVG files using the vulnerable \u003ccode\u003eremoveScripts\u003c/code\u003e plugin and subsequently renders these files in a victim's browser session. By leveraging these bypasses, an attacker can execute arbitrary JavaScript within the context of the affected application's origin. This can lead to session hijacking via cookie theft, unauthorized actions performed on behalf of the user, or manipulation of the application's DOM. The severity is heightened for applications that serve user-uploaded SVGs in same-origin contexts.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch immediately by upgrading to the designated fixed versions: upgrade v2 users to 2.8.4, v3 users to 3.3.5, and v4 users to 4.1.0.\u003c/li\u003e\n\u003cli\u003eFor applications handling hostile or untrusted SVG input, implement a dedicated SVG sanitization library (such as DOMPurify) as a pre-processing step before passing input to SVGO.\u003c/li\u003e\n\u003cli\u003eWhere possible, serve user-controlled SVG files in a sandboxed, cross-origin context (e.g., using a dedicated domain or Content-Security-Policy headers) to minimize the impact of potential XSS.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-08T21:50:33Z","date_published":"2026-09-08T21:50:33Z","id":"https://feed.craftedsignal.io/briefs/2026-09-svgo-xss-bypass/","summary":"The SVGO 'removeScripts' plugin is vulnerable to XSS bypasses due to insufficient validation of namespace-prefixed SVG anchors and control-character obfuscation in URL schemes, potentially allowing script execution when untrusted SVG content is rendered.","title":"SVGO removeScripts Plugin XSS Bypass","url":"https://feed.craftedsignal.io/briefs/2026-09-svgo-xss-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Svgo (3.x \u003c 3.3.5)","version":"https://jsonfeed.org/version/1.1"}