Intel

AIKIDO-2026-10354

milsymbol is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 13, 2026

68

Medium Risk

This Affects:

JSmilsymbol
1.0.0 - 3.0.3
Fixed in 3.0.4
Are you affected? Scan for Free

TL;DR

Affected versions of this package contain a Cross-Site Scripting (XSS) vulnerability in the SVG generation logic, where user-supplied input was inserted into the SVG output without proper parsing or sanitization. It could allow malicious markup or JavaScript to be embedded within the generated SVG. An attacker might exploit this by injecting crafted payloads that execute when the SVG is rendered in a browser, potentially enabling session theft, credential harvesting, or arbitrary script execution in the victim’s context.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

milsymbol is vulnerable to Cross-site Scripting (XSS) in versions 1.0.0 - 3.0.3.

How to fix this

Upgrade the milsymbol library to the patch version.