DbGate has cross site scripting via the SVG Icon String Handler component
- Severity:
- Low
Description
A security vulnerability has been detected in DbGate up to 7.1.4. This affects an unknown function of the file packages/web/src/icons/FontIcon.svelte of the component SVG Icon String Handler. Such manipulation of the argument applicationIcon leads to cross site scripting. The attack may be launched remotely.
Recommendation
Update the dbgate-web package to the latest compatible version. Followings are version details:
- Affected version(s): < 7.1.5
- Patched version(s): 7.1.5
References
Related Issues
- Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization - CVE-2026-65841
- Open WebUI Has Stored Cross-Site Scripting in SVG Renderer - CVE-2026-45346
- Svelte SSR vulnerable to cross-site scripting via spread attributes - CVE-2026-42599
- NotChatbot WebChat has a stored cross-site scripting (XSS) vulnerability - CVE-2026-30048
You might also like:
- Tags:
- npm
- dbgate-web
Anything's wrong? Let us know Last updated on April 14, 2026


