GSA / GSA/data.gov

Snyk Finding: Cross-site Scripting (XSS)

Open Beginner friendly
#6,289 1 comment 0 reactions 0 assignees View on GitHub
bug O&M Security - compliance
Dominant language
Python
Stars
1.1k
Forks
200
Avg merge
4h 56m
Merged PRs (30d)
5

Description

**Date of report:** 2026-09-01
**Severity:** MEDIUM
**Due date:** 2026-11-30

_Due date is based on severity and described in RA-5. 15-days for Critical, 30-days for High, and 90-days for Moderate and lower._

- [ ] Analysis has been performed and an issue has been linked to address other occurrences for this class of vulnerability\* (_link_)

_\* When a finding is identified, we create two issues. One to address the specific instance identified in the report. The other is to identify and address all other occurrences of this vulnerability within the application._

### Brief description
[SNYK-JS-SVGO-19498536](https://security.snyk.io/vuln/SNYK-JS-SVGO-19498536)
Per the snyk suggestion Upgrade svgo to version 2.8.4, 3.3.5, 4.1.0 or higher.

Contributor guide

Open the contributing guide

Research direction

Start with the linked Snyk advisory for SNYK-JS-SVGO-19498536 and locate the dependency declaration for svgo in the repository. Upgrade svgo to 2.8.4, 3.3.5, 4.1.0, or higher, then verify the application checks pass and complete the analysis checkbox for related occurrences.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
64/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.