VYPR

Sanitize Svg

by Sanitize Svg Project

CVEs (1)

  • CVE-2023-22461HigJan 4, 2023
    risk 0.42cvss 7.6epss 0.01

    The `sanitize-svg` package, a small SVG sanitizer to prevent cross-site scripting attacks, uses a deny-list-pattern to sanitize SVGs to prevent XSS. In doing so, literal ``-tags and on-event handlers were detected in versions prior to 0.4.0. As a result, downstream…