Vulnerabilities/

Fiora chat group avatar is vulnerable to XSS via SVG files

Severity:
Low

Description

File upload vulnerability in Fiora chat application 1.0.0 through user avatar upload functionality. The application fails to validate SVG file content, allowing malicious SVG files with embedded foreignObject elements containing iframe tags and JavaScript event handlers (onmouseover) to be uploaded and stored.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
fiora
Anything's wrong? Let us know Last updated on October 01, 2025