Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2026-84369

21 день назад

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, named removeScriptElement in versions 2 and 3 and implemented in plugins/removeScripts.js, removes SVG and XHTML script elements but does not inspect executable HTML content inside SVG foreignObject elements. Event-handler attributes such as onload and onbeforetoggle, srcdoc documents, and executable URLs in the action, data, formaction, href, and src attributes can remain in attacker-controlled SVG input. When an application uses the plugin as its only protection and serves the optimized SVG in an active browser context, the payload can execute script in the viewer's origin, expose data, modify content, or perform actions as the victim. This issue is fixed in versions 2.8.4, 3.3.5, and 4.1.0.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2026-84369

21 день назад

SVGO, short for SVG Optimizer, is a Node.js library and command-line a ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4vpr-x523-8j87

14 дней назад

SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-84369

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, named removeScriptElement in versions 2 and 3 and implemented in plugins/removeScripts.js, removes SVG and XHTML script elements but does not inspect executable HTML content inside SVG foreignObject elements. Event-handler attributes such as onload and onbeforetoggle, srcdoc documents, and executable URLs in the action, data, formaction, href, and src attributes can remain in attacker-controlled SVG input. When an application uses the plugin as its only protection and serves the optimized SVG in an active browser context, the payload can execute script in the viewer's origin, expose data, modify content, or perform actions as the victim. This issue is fixed in versions 2.8.4, 3.3.5, and 4.1.0.

CVSS3: 6.1
0%
Низкий
21 день назад
debian логотип
CVE-2026-84369

SVGO, short for SVG Optimizer, is a Node.js library and command-line a ...

CVSS3: 6.1
0%
Низкий
21 день назад
github логотип
GHSA-4vpr-x523-8j87

SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements

CVSS3: 6.1
0%
Низкий
14 дней назад

Уязвимостей на страницу