HasPrefix of the file /api/icon/getDynamicIcon. Performing a manipulation results in cross site scripting.This vulnerability is known as CVE-2026-31809. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.