HIGH
svg
CVE published 2026-09-01
CVE-2026-84370
The SVGO library and command-line application, used for optimizing SVG files, have a vulnerability in the removeScripts plugin. This plugin incompletely filters executable links, allowing an attacker to execute script in the SVG's origin, expose data, modify content, or perform actions as the victim when an application processes attacker-controlled SVG input and serves the result in an active browser cont [truncated]