EIP-2026-104087
PRE-CVESquiggle 1.7 - SVG Browser Java Code Execution (Metasploit)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104087. PoCs published by Metasploit.
AI-analyzed exploit summary This Metasploit module exploits a vulnerability in the Batik framework's Squiggle SVG Browser (version 1.7) by serving a crafted SVG file that references a malicious JAR, leading to arbitrary Java code execution. The exploit requires the target to have SVG 1.1+ support, Java enabled, and secure scripting disabled.
Description
Squiggle 1.7 - SVG Browser Java Code Execution (Metasploit)
Exploits (1)
This Metasploit module exploits a vulnerability in the Batik framework's Squiggle SVG Browser (version 1.7) by serving a crafted SVG file that references a malicious JAR, leading to arbitrary Java code execution. The exploit requires the target to have SVG 1.1+ support, Java enabled, and secure scripting disabled.