SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named r…
高危 CVSS 8.2
摘要
SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named removeScriptElement in versions 1 through 3, can leave executable content in optimized SVGs because it does not remove namespaced or prefixed script elements such as <svg:script> and, in versions 3 and 4, matches JavaScript URIs case sensitively. Applications that process untrusted SVG input with thi…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://github.com/svg/svgo/commit/628e3bc7336625a30365d0a9b60185307d852466
- https://github.com/svg/svgo/commit/72a23886b4698b27624b936f3a15a80afd36d75f
- https://github.com/svg/svgo/commit/f529cfccc6c154d6f6eabe276ec637a8c5db6763
- https://github.com/svg/svgo/releases/tag/v2.8.3
- https://github.com/svg/svgo/releases/tag/v3.3.4
- https://github.com/svg/svgo/releases/tag/v4.0.2
- https://github.com/svg/svgo/security/advisories/GHSA-2p49-hgcm-8545
时间线
- nvd_ingest NVD