{"id":"GHSA-cf4q-4cqr-7g7w","aliases":[],"url":"https://o3.security/vulnerability/GHSA-cf4q-4cqr-7g7w","summary":"SVG with embedded scripts can lead to cross-site scripting attacks in xml2rfc","details":"xml2rfc allows `script` elements in SVG sources.\nIn HTML output having these script elements can lead to XSS attacks.\n\nSample XML snippet:\n```\n<artwork type=\"svg\" src=\"data:image/svg+xml,%3Csvg viewBox='0 0 10 10' xmlns='http://www.w3.org/2000/svg'%3E%3Cscript%3E window.alert('Test Alert'); %3C/script%3E%3C/svg%3E\">\n</artwork>\n```\n\n### Impact\nThis vulnerability impacts website that publish HTML drafts and RFCs.\n\n### Patches\nThis has been fixed in version [3.12.4](https://github.com/ietf-tools/xml2rfc/releases/tag/v3.12.4).\n\n### Workarounds\nIf SVG source is self-contained within the XML, scraping `script` elements from SVG files.\n\n### References\n* https://developer.mozilla.org/en-US/docs/Web/SVG/Element/script\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [xml2rfc](https://github.com/ietf-tools/xml2rfc/)\n* Email us at [operational-vulnerability@ietf.org](mailto:operational-vulnerability@ietf.org)\n* [Infrastructure and Services Vulnerability Disclosure](https://www.ietf.org/about/administration/policies-procedures/vulnerability-disclosure/)\n","published":"2022-04-22T20:25:53Z","modified":"2024-12-05T05:42:31.021439Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"xml2rfc","fixedVersion":"3.12.4"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/ietf-tools/xml2rfc/security/advisories/GHSA-cf4q-4cqr-7g7w"},{"type":"PACKAGE","url":"https://github.com/ietf-tools/xml2rfc"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-05T05:42:31.021439Z"}}