Description
Improper sanitization of the value of the ‘href’ and ‘xlink:href’ attributes in ‘
Recommendation
No fix is available yet. Followings are affected versions:
- >= 1.3.1, <= 1.8.3
References
- GHSA-4p4w-6hg8-63wx
- codepen.io
- www.herodevs.com
- lists.debian.org
- CVE-2025-2336
- CWE-791
- CAPEC-310
- OWASP 2021-A6
Related Issues
- Validator is Vulnerable to Incomplete Filtering of One or More Instances of Special Elements - CVE-2025-12758
- AngularJS improperly sanitizes SVG elements - CVE-2025-0716
- Nuxt MDC has an XSS vulnerability in markdown rendering that bypasses HTML filtering - CVE-2025-54075
- @octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtrack - CVE-2025-25289
You might also like:
- Tags:
- npm
- angular-sanitize
Anything's wrong? Let us know Last updated on November 03, 2025


