Impact
A user visiting a malicious document and previewing an attachment could have their account compromised, because JavaScript in an SVG file would be evaluated in the context of their current page.
Patches
Fixed since version 1.3.2
Mitigation was to add an appropriate content security policy for attachments.
Workarounds
Avoid previewing attachments in documents prepared by people you do not trust.
References
Impact
A user visiting a malicious document and previewing an attachment could have their account compromised, because JavaScript in an SVG file would be evaluated in the context of their current page.
Patches
Fixed since version 1.3.2
Mitigation was to add an appropriate content security policy for attachments.
Workarounds
Avoid previewing attachments in documents prepared by people you do not trust.
References