CVE-2025-55166 | darylldoyle svg-sanitizer up to 0.21.x Attribute Name cleanXlinkHrefs cross site scripting (WID-SEC-2025-1834)
A vulnerability labeled as problematic has been found in darylldoyle svg-sanitizer up to 0.21.x. This affects the function cleanXlinkHrefs of the component Attribute Name Handler. Such manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-55166. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.