Improper Control of Generation of Code ('Code Injection') vulnerability in liuyueyi quick-media (plugins/svg-plugin/batik-codec-fix/src/main/java/org/apache/batik/ext/awt/image/codec/png modules). This vulnerability is associated with program files PNGImageEncoder.Java.
This issue affects all quick-media versions. A patch is available: e52fcee
{
"cwe_ids": [
"CWE-94"
],
"severity": "MODERATE",
"nvd_published_at": "2026-01-27T09:15:50Z",
"github_reviewed": true,
"github_reviewed_at": "2026-01-28T15:52:10Z"
}