Moderate severityNVD Advisory· Published Nov 22, 2023· Updated Aug 2, 2024
CVE-2023-49146
CVE-2023-49146
Description
DOMSanitizer (aka dom-sanitizer) before 1.0.7 allows XSS via an SVG document because of mishandling of comments and greedy regular expressions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
rhukster/dom-sanitizerPackagist | < 1.0.7 | 1.0.7 |
Affected products
2Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.