Skip to content

Snyk Finding: Cross-site Scripting (XSS) #6289

Description

@marcos-nieto-usds

Date of report: 2026-09-01
Severity: MEDIUM
Due date: 2026-11-30

Due date is based on severity and described in RA-5. 15-days for Critical, 30-days for High, and 90-days for Moderate and lower.

  • Analysis has been performed and an issue has been linked to address other occurrences for this class of vulnerability* (link)

* When a finding is identified, we create two issues. One to address the specific instance identified in the report. The other is to identify and address all other occurrences of this vulnerability within the application.

Brief description

SNYK-JS-SVGO-19498536
Per the snyk suggestion Upgrade svgo to version 2.8.4, 3.3.5, 4.1.0 or higher.

Activity

  1. added this to the 2026 11 milestone on Sep 4, 2026
  2. added
    O&MOperations and maintenance tasks for the Data.gov platform
    on Sep 4, 2026
  3. FuhuXia commented on Sep 4, 2026

    @FuhuXia
    Member

    Have you tried to update the version according to the snyk suggestion?
    If it take less time to create a PR and update it than creating this ticket and add to .snyk exception, you can just update it and get synk scan pass, no need to create a ticket for each snyk finding. If the PR failed and it is estimated to take some effort to do the update, then a ticket make sense to track the effort.

  4. moved this to O&M Specific Backlog in data.gov team boardon Sep 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    O&MOperations and maintenance tasks for the Data.gov platformSecurity - complianceRelating to security compliance or documentationbugSoftware defect or bug

    Type

    No type

    Projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions