There is a known vulnerability in the HTMLSanitzer.jl package in all versions below v0.2.1
. We recommend all users upgrade to version v0.2.1
as soon as possible.
More details here: Possible XSS in HTMLSanitizer when using svg elements · Advisory · JuliaComputing/HTMLSanitizer.jl · GitHub
This has been assigned CVE-2025-52561