The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents.Referenceshttps://github.com/fnando/svg_optimizer/pull/17https://github.com/rubysec/ruby-advisory-db/pull/713