Description
Cross Site Scripting (XSS) vulnerability in Fiora chat application 1.0.0 allows arbitrary JavaScript execution when malicious SVG files are rendered by other users.
Recommendation
No fix is available yet. Followings are affected versions:
- = 1.0.0
References
Related Issues
- Fiora chat group avatar is vulnerable to XSS via SVG files - CVE-2025-56515
- Lobe Chat Desktop vulnerable to Remote Code Execution via XSS in Chat Messages - CVE-2025-59417
- Bootstrap Multiselect Vulnerable to CSRF and Reflective XSS via Arbitrary POST Data - CVE-2025-47204
- Quill is vulnerable to XSS via HTML export feature - CVE-2025-15056
You might also like:
- Tags:
- npm
- fiora
Anything's wrong? Let us know Last updated on October 13, 2025


