Slink v1.4.9 allows stored cross-site scripting (XSS) via crafted SVG uploads. When a user views the shared image in a new browser tab, the embedded JavaScript executes. The issue affects both authenticated and unauthenticated users.
| Software | From | Fixed in |
|---|---|---|
| slinkapp / slink | 1.4.9 | 1.4.9.x |
| slinkapp / slink | 1.5.1 | 1.5.1.x |
| slinkapp / slink | 1.6.3 | 1.6.3.x |