CVE-2026-103687 | rhukster dom-sanitizer up to 1.0.15 SVG Sanitization src/DOMSanitizer.php url incomplete blacklist (GHSA-cjfg-j8jp-5xvc)

SecurityVulns

A vulnerability described as critical has been identified in rhukster dom-sanitizer up to 1.0.15. The affected element is the function url of the file src/DOMSanitizer.php of the component SVG Sanitization. Such manipulation leads to incomplete blacklist.

This vulnerability is referenced as CVE-2026-103687. It is possible to launch the attack remotely. Furthermore, an exploit is available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More