This minor release upgrades the SAX parser and introduces stricter XML validation. It also includes important security hardening for removeScripts, dependency updates, and improvements to the test and regression infrastructure.
Support SVGO
If SVGO is valuable to you or your organization, please consider supporting the project on OpenCollective. Your sponsorship helps fund ongoing maintenance and security work.
Stricter XML validation
SVGO now uses sax 1.6.1, upgraded from 1.5.0 (#2257).
The new parser version validates numeric character references against the ranges permitted by XML. Invalid references are now rejected in both text and attributes, including:
- disallowed control characters such as
,, and; - UTF-16 surrogate code points such as
�; - invalid XML code points such as
.
Valid boundary values—including U+0020, U+D7FF, U+E000, U+FFFD, and characters through U+10FFFF—remain supported.
Parser failures are consistently exposed as SvgoParserError errors with an Invalid character entity reason.
This is an intentional behavior change: malformed SVGs that were previously accepted may now produce a parser error, while valid XML documents are unaffected.
Security
The removeScripts plugin has been hardened against several script-execution bypasses:
- Filters executable
data:URLs containing HTML, XHTML, or SVG documents while preserving inert data such as PNG images, and filters legacyvbscript:URLs (#2263). - Sanitizes content inside SVG
<foreignObject>elements by removing HTML event-handler attributes,srcdoc, and executable URLs fromaction,data,formaction,href, andsrc, while preserving non-executable HTML and visual content (#2264). - Recognizes namespace-prefixed SVG
<a>elements and removes ASCII tabs and newlines before checking URL schemes, preventing values such asjava	script:from bypassing detection while preserving elements in unrelated custom namespaces (#2268).
These changes address:
Dependencies
- Upgraded
css-selectto v6 andcss-whatto v7, and updated SVGO's custom selector adapter forcss-selectv6 (#2244).
Project maintenance
@TrySound is back as an active SVGO maintainer.
Many thanks to @KTibow, @SethFalco, and @XhmikosR for maintaining and improving SVGO over the past several years.
Full Changelog: v4.0.2...v4.1.0