fig. 01 — GHSA-8xqr-4cpm-wx7g, the advisory selected below
// advisories
GHSA-8xqr-4cpm-wx7g
UNKNOWN
Versions of react-svg before 2.2.18 are vulnerable to cross-site scripting (xss). This is due to the fact that scripts found in SVG files are run by default.