All 4 CVE vulnerabilities found in svgo, with AI-generated Chinese analysis, references, and POCs.
Vendor: svg
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-84370 | SVGO: removeScripts allows executable links through namespace and control-character bypasses CWE-79 | 8.2 | High | 2026-09-01 |
| CVE-2026-84369 | SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements CWE-79 | 6.1 | Medium | 2026-09-01 |
| CVE-2026-73650 | SVGO: removeScripts plugin leaves some executable scripts intact CWE-79 | 8.2 | High | 2026-08-13 |
| CVE-2026-29074 | SVGO: DoS through entity expansion in DOCTYPE (Billion Laughs) CWE-776 | 7.5 | High | 2026-03-06 |
All 4 known CVE vulnerabilities affecting svgo with full Chinese analysis, references, and POCs where available.