Cross-Site Scripting in react-svg
High severity
GitHub Reviewed
Published
May 31, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
May 31, 2019
Published to the GitHub Advisory Database
May 31, 2019
Last updated
Jan 9, 2023
Versions of
react-svg
before 2.2.18 are vulnerable to cross-site scripting (xss). This is due to the fact that scripts found in SVG files are run by default.Recommendation
Update to version 2.2.18 or later.
References