dompurify prior to version 2.2.2 is vulnerable to cross-site scripting when converting from SVG namespace. References https://github.com/cure53/DOMPurify/issues/482 https://github.com/cure53/DOMPurify/releases/tag/2.2.2 https://security.snyk.io/vuln/SNYK-JS-DOMPURIFY-1035544 https://github.com/advisories/GHSA-pgjv-jrg2-gq3v