VYPR

npm package

@mattkrick/sanitize-svg

pkg:npm/%40mattkrick/sanitize-svg

Vulnerabilities (1)

  • CVE-2023-22461Jan 4, 2023
    affected < 0.4.0fixed 0.4.0

    The `sanitize-svg` package, a small SVG sanitizer to prevent cross-site scripting attacks, uses a deny-list-pattern to sanitize SVGs to prevent XSS. In doing so, literal ``-tags and on-event handlers were detected in versions prior to 0.4.0. As a result, downstream softwa