Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-w27v-7q3p-w38r
  • npm/svgo
SVGO: removeScripts allows executable links through namespace and control-character bypasses 08 Sep
  • Fix available
  • Severity - 8.2 (High)
GHSA-4vpr-x523-8j87
  • npm/svgo
SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements 08 Sep
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-2p49-hgcm-8545
  • npm/svgo
SVGO removeScripts plugin leaves some executable scripts intact 21 Jul
  • Fix available
  • Severity - 8.2 (High)
MAL-2026-10482
  • npm/react-icons-svgo
Malicious code in react-icons-svgo (npm) 13 Jul
  • No fix available
GHSA-xpqw-6gx7-v673
  • npm/svgo
SVGO DoS through entity expansion in DOCTYPE (Billion Laughs) 04 Mar
  • Fix available
  • Severity - 7.5 (High)
MAL-2024-3068
  • npm/svgo-compressor
Malicious code in svgo-compressor (npm) 25 Jun 2024
  • No fix available
MAL-2022-6371
  • npm/svgo-ruby
Malicious code in svgo-ruby (npm) 20 Jun 2022
  • No fix available
MAL-2022-5371
  • npm/plugin-svgo
Malicious code in plugin-svgo (npm) 20 Jun 2022
  • No fix available