milsymbol is vulnerable to Cross-site Scripting (XSS)
68
Medium Risk
Affected versions of this package contain a Cross-Site Scripting (XSS) vulnerability in the SVG generation logic, where user-supplied input was inserted into the SVG output without proper parsing or sanitization. It could allow malicious markup or JavaScript to be embedded within the generated SVG. An attacker might exploit this by injecting crafted payloads that execute when the SVG is rendered in a browser, potentially enabling session theft, credential harvesting, or arbitrary script execution in the victim’s context.
You are affected if you are using a version that falls within the vulnerable range.
milsymbol is vulnerable to Cross-site Scripting (XSS) in versions 1.0.0 - 3.0.3.
Upgrade the milsymbol library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant