{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/rhukster/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rhukster:dom-sanitizer:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-103687"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["dom-sanitizer (\u003c= 1.0.15)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["rhukster"],"content_html":"\u003cp\u003eA security vulnerability identified as CVE-2026-103687 exists within the rhukster dom-sanitizer library, specifically affecting versions up to and including 1.0.15. The issue is located in the SVG Sanitization component, within the \u003ccode\u003eurl\u003c/code\u003e function of \u003ccode\u003esrc/DOMSanitizer.php\u003c/code\u003e. The vulnerability stems from an incomplete blacklist implementation, which allows remote attackers to supply specially crafted input that evades existing sanitization logic. This flaw can lead to cross-site scripting (XSS) or other injection-based attacks if the library is used to process untrusted user content. Exploitation can be performed remotely by submitting malicious payloads to applications utilizing the affected library. The maintainers have released a fix in version 1.0.16.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows remote attackers to bypass sanitization filters, potentially leading to unauthorized script execution in the context of the user's browser. This could be used to facilitate session hijacking, data theft, or other malicious actions within web applications relying on this library for SVG sanitization.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for development and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the rhukster dom-sanitizer library to version 1.0.16 or later to address CVE-2026-103687.\u003c/li\u003e\n\u003cli\u003eReview applications utilizing the library to ensure input processed by the SVG Sanitization component is validated against an updated security policy.\u003c/li\u003e\n\u003cli\u003ePerform code reviews on implementations using the \u003ccode\u003eurl\u003c/code\u003e function within \u003ccode\u003esrc/DOMSanitizer.php\u003c/code\u003e to identify any existing payloads leveraging the incomplete blacklist.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T16:12:15Z","date_published":"2026-10-01T16:12:15Z","id":"https://feed.craftedsignal.io/briefs/2026-10-dom-sanitizer-xss/","summary":"The SVG Sanitization component in rhukster dom-sanitizer versions 1.0.15 and earlier contains an incomplete blacklist vulnerability in src/DOMSanitizer.php, allowing remote attackers to bypass security filters via malicious URL inputs.","title":"Incomplete Blacklist Vulnerability in rhukster dom-sanitizer","url":"https://feed.craftedsignal.io/briefs/2026-10-dom-sanitizer-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Rhukster","version":"https://jsonfeed.org/version/1.1"}