CRITICAL9.6
GHSA-j977-g5vj-j27g
Cross-Site Scripting in scratch-svg-renderer
Quick fix
GHSA-j977-g5vj-j27g — scratch-svg-renderer: upgrade to the fixed version with the command below.
npm install scratch-svg-renderer@0.2.0-prerelease.20201019174008Details
This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not escape SVG properly, which can be used to inject arbitrary elements into the DOM via the _transformMeasurements function.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/scratch-svg-renderer
Introduced in:
0Fixed in: 0.2.0-prerelease.20201019174008Fix
npm install scratch-svg-renderer@0.2.0-prerelease.20201019174008