Vulnerabilities/

Fiora chat user avatar is vulnerable to XSS via SVG files

Severity:
Low

Description

Cross Site Scripting (XSS) vulnerability in Fiora chat application 1.0.0 allows arbitrary JavaScript execution when malicious SVG files are rendered by other users.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
fiora
Anything's wrong? Let us know Last updated on October 13, 2025