@vendure/asset-server-plugin is vulnerable to Cross-Site Scripting (XSS)
48
Medium Risk
The asset server permits SVG uploads by default and serves them with Content-Type image/svg+xml without sanitization. Embedded JavaScript in an uploaded SVG executes when a victim opens the asset URL directly, allowing an administrator with upload rights to persist scripts that run in other users' browsers. The fix removes SVG from the default permitted types, sanitizes SVG content, serves such assets as attachments, and strengthens the content security policy headers.
You are affected if you are using a version that falls within the vulnerable range and you permit SVG uploads and serve them through the asset server.
@vendure/asset-server-plugin is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 3.7.2.
Upgrade the @vendure/asset-server-plugin library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.