Skip to content

Fixes CVE-2025-55166#17601

Merged
snipe merged 1 commit intogrokability:developfrom
ubc-cpsc:bugfix/CVE-2025-55166
Aug 13, 2025
Merged

Fixes CVE-2025-55166#17601
snipe merged 1 commit intogrokability:developfrom
ubc-cpsc:bugfix/CVE-2025-55166

Conversation

@joelpittet
Copy link
Copy Markdown
Contributor

Description

❯ composer audit
Found 1 security vulnerability advisory affecting 1 package:
+-------------------+----------------------------------------------------------------------------------+
| Package           | enshrined/svg-sanitize                                                           |
| Severity          | medium                                                                           |
| CVE               | CVE-2025-55166                                                                   |
| Title             | svg-sanitizer Bypasses Attribute Sanitization                                    |
| URL               | https://github.com/advisories/GHSA-22wq-q86m-83fh                                |
| Affected versions | <0.22.0                                                                          |
| Reported at       | 2025-08-12T20:20:58+00:00                                                        |
+-------------------+----------------------------------------------------------------------------------+

Type of change

  • Bug fix (non-breaking change which fixes an issue)

How Has This Been Tested?

composer audit

Test Configuration:

  • PHP version: 8.3
  • MySQL version: 8.0
  • Webserver version: N/A
  • OS version: macOS

Checklist:

@joelpittet joelpittet requested a review from snipe as a code owner August 13, 2025 18:46
@snipe
Copy link
Copy Markdown
Member

snipe commented Aug 13, 2025

Thank you (from Germany)!

@snipe snipe merged commit 376e0db into grokability:develop Aug 13, 2025
7 of 8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants