Tag
The SVGO 'removeScripts' plugin is vulnerable to XSS bypasses due to insufficient validation of namespace-prefixed SVG anchors and control-character obfuscation in URL schemes, potentially allowing script execution when untrusted SVG content is rendered.