Executive brief
SVG Formatter module provides support for using SVG images on your website.
This security release fixes third-party dependencies included in or required by SVG Formatter. [XSS bypass using entities and tab](https://github.com/darylldoyle/svg-sanitizer/issues/31).
This vulnerability is mitigated by the fact that an attacker must be able to upload SVG files.
Affected products
- packagist:https://packages.drupal.org/8 drupal/svg_formatter