Vulnerabilities/

external-svg-loader Cross-site Scripting vulnerability

Severity:
High

Description

According to the docs, svg-loader will strip all JS code before injecting the SVG file for security reasons but the input sanitization logic is not sufficient and can be trivially bypassed. This allows an attacker to craft a malicious SVG which can result in XSS.

Recommendation

Update the external-svg-loader package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
external-svg-loader
Anything's wrong? Let us know Last updated on November 08, 2023

This issue is available in SmartScanner Professional

See Pricing