• svgo2 vulnerabilities

Showing 2 vulnerabilities on this page for svgo

Signals CISA KEV Ransomware Nuclei
svg vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

SVGO: removeScripts plugin leaves some executable scripts intact

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named removeScriptElement in versions 1 through 3, can leave executable content in optimized SVGs because it does not remove namespaced or prefixed script elements such as <svg:script> and, in versions 3 and 4, matches JavaScript URIs case sensitively. Applications that process untrusted SVG input with this

CWE-184CWE-79Aug 13, 2026
CVSS8.2v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SVGO: DoS through entity expansion in DOCTYPE (Billion Laughs)

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 2.1.0 to before version 2.8.1, from version 3.0.0 to before version 3.3.3, and before version 4.0.1, SVGO accepts XML with custom entities, without guards against entity expansion or recursion. This can result in a small XML file (811 bytes) stalling the application and even crashing the Node.js process with JavaScript heap out of memory. This issue has been patched in versions

CWE-776Mar 6, 2026
CVSS7.5v3.1EPSS0.612%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX