Snyk Finding: Cross-site Scripting (XSS)
- Dominant language
- Python
- Stars
- 1.1k
- Forks
- 200
- Avg merge
- 4h 56m
- Merged PRs (30d)
- 5
Description
**Date of report:** 2026-09-01
**Severity:** MEDIUM
**Due date:** 2026-11-30
_Due date is based on severity and described in RA-5. 15-days for Critical, 30-days for High, and 90-days for Moderate and lower._
- [ ] Analysis has been performed and an issue has been linked to address other occurrences for this class of vulnerability\* (_link_)
_\* When a finding is identified, we create two issues. One to address the specific instance identified in the report. The other is to identify and address all other occurrences of this vulnerability within the application._
### Brief description
[SNYK-JS-SVGO-19498536](https://security.snyk.io/vuln/SNYK-JS-SVGO-19498536)
Per the snyk suggestion Upgrade svgo to version 2.8.4, 3.3.5, 4.1.0 or higher.
Contributor guide
Research direction
Start with the linked Snyk advisory for SNYK-JS-SVGO-19498536 and locate the dependency declaration for svgo in the repository. Upgrade svgo to 2.8.4, 3.3.5, 4.1.0, or higher, then verify the application checks pass and complete the analysis checkbox for related occurrences.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 64/100