Related Vulnerabilities: CVE-2020-26956  

A security issue has been found in Firefox before 83.0 where, in some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS.

Severity Medium

Remote Yes

Type Cross-site scripting

Description

A security issue has been found in Firefox before 83.0 where, in some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS.

AVG-1279 firefox 82.0.3-1 83.0-1 Critical Fixed

https://www.mozilla.org/en-US/security/advisories/mfsa2020-50/#CVE-2020-26956