Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade satori to version 0.33.5 or higher.
satori is an Enlightened library to convert HTML and CSS to SVG.
Affected versions of this package are vulnerable to Improper Encoding or Escaping of Output in the generation of its SVG output, which places certain input values into the document without neutralizing characters that are significant in markup, so those values are parsed as SVG elements rather than as content. An attacker can inject markup of their choosing into the rendered document, by supplying a value that reaches one of the unescaped positions, such as text or an attribute drawn from user data. This requires the application to render attacker-influenced content, and the consequence depends on how the output is consumed, since an SVG embedded inline in a page is parsed in that page's origin while one referenced through an img element is not.