Description
File upload vulnerability in Fiora chat application 1.0.0 through user avatar upload functionality. The application fails to validate SVG file content, allowing malicious SVG files with embedded foreignObject elements containing iframe tags and JavaScript event handlers (onmouseover) to be uploaded and stored.
Recommendation
No fix is available yet. Followings are affected versions:
- = 1.0.0
References
Could your website be exposed too?
SmartScanner can check your website for Fiora chat group avatar is vulnerable to XSS via SVG files and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Fiora chat user avatar is vulnerable to XSS via SVG files - CVE-2025-56514
- Lobe Chat Desktop vulnerable to Remote Code Execution via XSS in Chat Messages - CVE-2025-59417
- Quill is vulnerable to XSS via HTML export feature - CVE-2025-15056
- Open WebUI Vulnerable to Stored DOM XSS via Note 'Download PDF - CVE-2025-65959


