CVE-2025-56514

EPSS 0.01%

Fiora chat user avatar is vulnerable to XSS via SVG files

Published: 10/1/2025Modified: 10/13/2025
Also known as:GHSA-hg3j-6pmh-mvjr

Description

Cross Site Scripting (XSS) vulnerability in Fiora chat application 1.0.0 allows arbitrary JavaScript execution when malicious SVG files are rendered by other users.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P

References (4)