THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-g8qq-57p8-ggw5 (medium) — ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass

[GHSA] GHSA-g8qq-57p8-ggw5 (medium) — ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass

medgithub_advisoriesPublished 2026-09-01

GHSA-g8qq-57p8-ggw5 Severity: medium CVE: CVE-2026-84371

ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass

### Summary When SVG animation is allowed, `attributeName="href"` makes `values` a list of URL destinations. `sanitize-html` accepts a list that starts with a safe fragment even when `values` is explicitly scheme-checked, allowing a later `javascript:` destination to exec

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-g8qq-57p8-ggw5