VDB
Sign up
CRITICAL9.6

GHSA-j977-g5vj-j27g

Cross-Site Scripting in scratch-svg-renderer

Quick fix

GHSA-j977-g5vj-j27g — scratch-svg-renderer: upgrade to the fixed version with the command below.

npm install scratch-svg-renderer@0.2.0-prerelease.20201019174008

Details

This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not escape SVG properly, which can be used to inject arbitrary elements into the DOM via the _transformMeasurements function.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/scratch-svg-renderer
Introduced in: 0Fixed in: 0.2.0-prerelease.20201019174008
Fixnpm install scratch-svg-renderer@0.2.0-prerelease.20201019174008

References