In Progress Telerik UI for WinUI versions prior to 2025 Q1 (3.0.0), a command injection attack is possible through improper neutralization of hyperlink elements.Referenceshttps://docs.telerik.com/devtools/winui/security/kb-security-command-injection-cve-2024-12251