jeerbl/webfonts-loader

Security issue: Misinterpretation of malicious XML input

mzabuawala opened this issue · 3 comments

This seems to be an issue of @vusion/webfonts-generator, which depends on svg2ttf@5 and had to update to svg2ttf@6

Even svg2ttf@6 does use xmldom ~0.6.0. So they have to update to xmldom >= 0.7.0 too.

Stale issue message