CVE-2026-84371
published 2026-09-01CVE-2026-84371: ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0…
PriorityP428medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.30%
20.5th percentile
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting href or xlink:href gives the sibling values, from, to, or by attribute SVG SMIL URL semantics. In configurations that allow the animate, animateColor, animateMotion, animateTransform, or set elements, a values list can begin with a safe fragment and contain a later executable destination that survives allowedSchemesAppliedToAttributes checking. When the sanitized SVG is rendered, the browser can copy that later destination into the live link, and a victim who activates the link can execute script in the application's origin. This issue is fixed in version 2.17.7.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apostrophecms | apostrophe | — | — |
| apostrophecms | sanitize-html | >= 1.9.0 < 2.17.7 | 2.17.7 |
| costmanagement | costmanagement-ui-rhel10 | — | — |
| devspaces | dashboard-rhel9 | — | — |
| multicluster-engine | console-mce-rhel9 | — | — |
| openshift4 | ose-agent-installer-ui-rhel9 | — | — |
| openshift4 | ose-console | — | — |
| openshift4 | ose-console-rhel9 | — | — |
| quay | quay-rhel8 | — | — |
| quay | quay-rhel9 | — | — |
| rhacm2 | console-rhel9 | — | — |
| rhoai | odh-mlflow-rhel9 | — | — |
| satellite | iop-advisor-frontend-rhel9 | — | — |
| satellite | iop-host-inventory-frontend-rhel9 | — | — |
| satellite | iop-vulnerability-frontend-rhel9 | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
ApostropheCMS Apostrophe up to 2.17.6 HTML Sanitizer index.js HTML injection (EUVD-2026-69654)
vuldb·2026-09-02·CVSS 5.4
CVE-2026-84371 [MEDIUM] ApostropheCMS Apostrophe up to 2.17.6 HTML Sanitizer index.js HTML injection (EUVD-2026-69654)
A vulnerability marked as problematic has been reported in ApostropheCMS Apostrophe up to 2.17.6. This issue affects some unknown processing of the file packages/sanitize-html/index.js of the component HTML Sanitizer. Performing a manipulation results in HTML injection.
This vulnerability was named CVE-2026-84371. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
GHSA
ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass
ghsa·2026-09-01
CVE-2026-84371 [MEDIUM] CWE-79 ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass
ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass
### Summary
When SVG animation is allowed, `attributeName="href"` makes `values` a list of URL destinations. `sanitize-html` accepts a list that starts with a safe fragment even when `values` is explicitly scheme-checked, allowing a later `javascript:` destination to execute when the sanitized link is activated.
### Details
`index.js:371-383` validates each attribute as one flat URL. It does not recognize that `attributeName="href"` gives the sibling `values` attribute SMIL URI-list semantics. For `values="#safe;javascript:..."`, the leading fragment passes the flat check and the complete list is retained.
### PoC
This was reproduced with `[email protected]` and Chromium 150.0.7871.124. The configuration adds SVG an
Red Hat
sanitize-html: stored XSS via SVG SMIL URI-list scheme-policy bypass
vendor_redhat·2026-09-01·CVSS 5.4
CVE-2026-84371 [MEDIUM] CWE-79 sanitize-html: stored XSS via SVG SMIL URI-list scheme-policy bypass
sanitize-html: stored XSS via SVG SMIL URI-list scheme-policy bypass
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting href or xlink:href gives the sibling values, from, to, or by attribute SVG SMIL URL semantics. In configurations that allow the animate, animateColor, animateMotion, animateTransform, or set elements, a values list can begin with a safe fragment and contain a later executable destination that survives allowedSchemesAppliedToAttributes checking. When the sanitized SVG is rendered, the browser can copy that later
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-84371 python-jupyterlab-widgets: stored XSS via SVG SMIL URI-list scheme-policy bypass [epel-all]
bugzilla·2026-09-02·CVSS 5.4
CVE-2026-84371 [MEDIUM] CVE-2026-84371 python-jupyterlab-widgets: stored XSS via SVG SMIL URI-list scheme-policy bypass [epel-all]
CVE-2026-84371 python-jupyterlab-widgets: stored XSS via SVG SMIL URI-list scheme-policy bypass [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting href or xlink:href gives the sibling values, from, to, or by attribute SVG SMIL URL semantics. In configurations that allow the animate, animateColor,
Bugzilla
CVE-2026-84371 glances: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
bugzilla·2026-09-02·CVSS 5.4
CVE-2026-84371 [MEDIUM] CVE-2026-84371 glances: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
CVE-2026-84371 glances: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting href or xlink:href gives the sibling values, from, to, or by attribute SVG SMIL URL semantics. In configurations that allow the animate, animateColor, animateMotion, a
Bugzilla
CVE-2026-84371 python-jupyterlab_pygments: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
bugzilla·2026-09-02·CVSS 5.4
CVE-2026-84371 [MEDIUM] CVE-2026-84371 python-jupyterlab_pygments: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
CVE-2026-84371 python-jupyterlab_pygments: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting href or xlink:href gives the sibling values, from, to, or by attribute SVG SMIL URL semantics. In configurations that allow the animate, animateColo
Bugzilla
CVE-2026-84371 python-nbdime: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
bugzilla·2026-09-02·CVSS 5.4
CVE-2026-84371 [MEDIUM] CVE-2026-84371 python-nbdime: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
CVE-2026-84371 python-nbdime: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting href or xlink:href gives the sibling values, from, to, or by attribute SVG SMIL URL semantics. In configurations that allow the animate, animateColor, animateMot
Bugzilla
CVE-2026-84371 jupyterlab: stored XSS via SVG SMIL URI-list scheme-policy bypass [epel-all]
bugzilla·2026-09-02·CVSS 5.4
CVE-2026-84371 [MEDIUM] CVE-2026-84371 jupyterlab: stored XSS via SVG SMIL URI-list scheme-policy bypass [epel-all]
CVE-2026-84371 jupyterlab: stored XSS via SVG SMIL URI-list scheme-policy bypass [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting href or xlink:href gives the sibling values, from, to, or by attribute SVG SMIL URL semantics. In configurations that allow the animate, animateColor, animateMotion,
Bugzilla
CVE-2026-84371 python-ipyparallel: stored XSS via SVG SMIL URI-list scheme-policy bypass [epel-all]
bugzilla·2026-09-02·CVSS 5.4
CVE-2026-84371 [MEDIUM] CVE-2026-84371 python-ipyparallel: stored XSS via SVG SMIL URI-list scheme-policy bypass [epel-all]
CVE-2026-84371 python-ipyparallel: stored XSS via SVG SMIL URI-list scheme-policy bypass [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting href or xlink:href gives the sibling values, from, to, or by attribute SVG SMIL URL semantics. In configurations that allow the animate, animateColor, animate
Bugzilla
CVE-2026-84371 glances: stored XSS via SVG SMIL URI-list scheme-policy bypass [epel-all]
bugzilla·2026-09-02·CVSS 5.4
CVE-2026-84371 [MEDIUM] CVE-2026-84371 glances: stored XSS via SVG SMIL URI-list scheme-policy bypass [epel-all]
CVE-2026-84371 glances: stored XSS via SVG SMIL URI-list scheme-policy bypass [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting href or xlink:href gives the sibling values, from, to, or by attribute SVG SMIL URL semantics. In configurations that allow the animate, animateColor, animateMotion, ani
Bugzilla
CVE-2026-84371 prometheus: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
bugzilla·2026-09-02·CVSS 5.4
CVE-2026-84371 [MEDIUM] CVE-2026-84371 prometheus: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
CVE-2026-84371 prometheus: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting href or xlink:href gives the sibling values, from, to, or by attribute SVG SMIL URL semantics. In configurations that allow the animate, animateColor, animateMotion
Bugzilla
CVE-2026-84371 cockatrice: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
bugzilla·2026-09-02·CVSS 5.4
CVE-2026-84371 [MEDIUM] CVE-2026-84371 cockatrice: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
CVE-2026-84371 cockatrice: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting href or xlink:href gives the sibling values, from, to, or by attribute SVG SMIL URL semantics. In configurations that allow the animate, animateColor, animateMotion
Bugzilla
CVE-2026-84371 jupyterlab: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
bugzilla·2026-09-02·CVSS 5.4
CVE-2026-84371 [MEDIUM] CVE-2026-84371 jupyterlab: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
CVE-2026-84371 jupyterlab: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting href or xlink:href gives the sibling values, from, to, or by attribute SVG SMIL URL semantics. In configurations that allow the animate, animateColor, animateMotion
Bugzilla
CVE-2026-84371 prometheus: stored XSS via SVG SMIL URI-list scheme-policy bypass [epel-all]
bugzilla·2026-09-02·CVSS 5.4
CVE-2026-84371 [MEDIUM] CVE-2026-84371 prometheus: stored XSS via SVG SMIL URI-list scheme-policy bypass [epel-all]
CVE-2026-84371 prometheus: stored XSS via SVG SMIL URI-list scheme-policy bypass [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting href or xlink:href gives the sibling values, from, to, or by attribute SVG SMIL URL semantics. In configurations that allow the animate, animateColor, animateMotion,
Bugzilla
CVE-2026-84371 golang-github-apache-beam-2: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
bugzilla·2026-09-02·CVSS 5.4
CVE-2026-84371 [MEDIUM] CVE-2026-84371 golang-github-apache-beam-2: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
CVE-2026-84371 golang-github-apache-beam-2: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting href or xlink:href gives the sibling values, from, to, or by attribute SVG SMIL URL semantics. In configurations that allow the animate, animateCol
Bugzilla
CVE-2026-84371 python-jupyterlab_pygments: stored XSS via SVG SMIL URI-list scheme-policy bypass [epel-all]
bugzilla·2026-09-02·CVSS 5.4
CVE-2026-84371 [MEDIUM] CVE-2026-84371 python-jupyterlab_pygments: stored XSS via SVG SMIL URI-list scheme-policy bypass [epel-all]
CVE-2026-84371 python-jupyterlab_pygments: stored XSS via SVG SMIL URI-list scheme-policy bypass [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting href or xlink:href gives the sibling values, from, to, or by attribute SVG SMIL URL semantics. In configurations that allow the animate, animateColor,
Bugzilla
CVE-2026-84371 python-ipyparallel: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
bugzilla·2026-09-02·CVSS 5.4
CVE-2026-84371 [MEDIUM] CVE-2026-84371 python-ipyparallel: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
CVE-2026-84371 python-ipyparallel: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting href or xlink:href gives the sibling values, from, to, or by attribute SVG SMIL URL semantics. In configurations that allow the animate, animateColor, anima
Bugzilla
CVE-2026-84371 python-jupytext: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
bugzilla·2026-09-02·CVSS 5.4
CVE-2026-84371 [MEDIUM] CVE-2026-84371 python-jupytext: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
CVE-2026-84371 python-jupytext: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting href or xlink:href gives the sibling values, from, to, or by attribute SVG SMIL URL semantics. In configurations that allow the animate, animateColor, animateM
Bugzilla
CVE-2026-84371 python-jupyterlab-widgets: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
bugzilla·2026-09-02·CVSS 5.4
CVE-2026-84371 [MEDIUM] CVE-2026-84371 python-jupyterlab-widgets: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
CVE-2026-84371 python-jupyterlab-widgets: stored XSS via SVG SMIL URI-list scheme-policy bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting href or xlink:href gives the sibling values, from, to, or by attribute SVG SMIL URL semantics. In configurations that allow the animate, animateColor
Bugzilla
CVE-2026-84371 sanitize-html: stored XSS via SVG SMIL URI-list scheme-policy bypass
bugzilla·2026-09-01·CVSS 5.4
CVE-2026-84371 [MEDIUM] CVE-2026-84371 sanitize-html: stored XSS via SVG SMIL URI-list scheme-policy bypass
CVE-2026-84371 sanitize-html: stored XSS via SVG SMIL URI-list scheme-policy bypass
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting href or xlink:href gives the sibling values, from, to, or by attribute SVG SMIL URL semantics. In configurations that allow the animate, animateColor, animateMotion, animateTransform, or set elements, a values list can begin with a safe fragment and contain a later executable destination that survives allowedSchemesAppliedToAttributes checking. When the sanitized SVG is rendered, the browser can
https://github.com/apostrophecms/apostrophe/blob/main/packages/sanitize-html/CHANGELOG.mdhttps://github.com/apostrophecms/apostrophe/commit/1135516a1a4a8f9638641c460488a43d8af20081https://github.com/apostrophecms/apostrophe/commit/38ff1106c8176b16c2da9872acd9b449adcbb949https://github.com/apostrophecms/apostrophe/pull/5552https://github.com/apostrophecms/apostrophe/security/advisories/GHSA-g8qq-57p8-ggw5
2026-09-01
Published