This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not escape SVG properly, which can be used to inject arbitrary elements into the DOM via the _transformMeasurements function.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| scratch-svg-renderer(npm) | 0 | 0.2.0-prerelease.20201019174008 | N/A |
CVSS Metrics