Cross-Site Scripting in react-svg
        
  High severity
        
          GitHub Reviewed
      
        Published
          May 31, 2019 
          to the GitHub Advisory Database
          •
          Updated Jan 9, 2023 
      
  
Description
        Reviewed
      May 31, 2019 
    
  
        Published to the GitHub Advisory Database
      May 31, 2019 
    
  
        Last updated
      Jan 9, 2023 
    
  
Versions of
react-svgbefore 2.2.18 are vulnerable to cross-site scripting (xss). This is due to the fact that scripts found in SVG files are run by default.Recommendation
Update to version 2.2.18 or later.
References