Source: node-svgo
Version: 3.3.2+ds-1
X-Debbugs-CC: [email protected]
Severity: important
Tags: security upstream

Hi,

The following vulnerabilities were published for node-svgo.

CVE-2026-29074[0]:
| SVGO, short for SVG Optimizer, is a Node.js library and command-line
| application for optimizing SVG files. From version 2.1.0 to before
| version 2.8.1, from version 3.0.0 to before version 3.3.3, and
| before version 4.0.1, SVGO accepts XML with custom entities, without
| guards against entity expansion or recursion. This can result in a
| small XML file (811 bytes) stalling the application and even
| crashing the Node.js process with JavaScript heap out of memory.
| This issue has been patched in versions 2.8.1, 3.3.3, and 4.0.1.


CVE-2026-73650[1]:
| SVGO, short for SVG Optimizer, is a Node.js library and command-line
| application for optimizing SVG files. From version 1.0.0 until
| versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named
| removeScriptElement in versions 1 through 3, can leave executable
| content in optimized SVGs because it does not remove namespaced or
| prefixed script elements such as <svg:script> and, in versions 3 and
| 4, matches JavaScript URIs case sensitively. Applications that
| process untrusted SVG input with this plugin enabled and serve the
| result can allow scripts to execute when another user opens the SVG,
| exposing local storage or cookies. This issue is fixed in versions
| 2.8.3, 3.3.4, and 4.0.2.


CVE-2026-84369[2]:
| SVGO, short for SVG Optimizer, is a Node.js library and command-line
| application for optimizing SVG files. From version 1.0.0 until
| versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin,
| named removeScriptElement in versions 2 and 3 and implemented in
| plugins/removeScripts.js, removes SVG and XHTML script elements but
| does not inspect executable HTML content inside SVG foreignObject
| elements. Event-handler attributes such as onload and
| onbeforetoggle, srcdoc documents, and executable URLs in the action,
| data, formaction, href, and src attributes can remain in attacker-
| controlled SVG input. When an application uses the plugin as its
| only protection and serves the optimized SVG in an active browser
| context, the payload can execute script in the viewer's origin,
| expose data, modify content, or perform actions as the victim. This
| issue is fixed in versions 2.8.4, 3.3.5, and 4.1.0.


CVE-2026-84370[3]:
| SVGO, short for SVG Optimizer, is a Node.js library and command-line
| application for optimizing SVG files. From version 1.0.0 until
| versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin,
| named removeScriptElement in versions 2 and 3, incompletely filters
| executable links in plugins/removeScripts.js and lib/svgo/tools.js.
| The plugin does not recognize namespace-prefixed SVG anchor elements
| such as svg:a with href or namespaced *:href values, and it does not
| remove ASCII tab, line-feed, or carriage-return characters before
| checking URL schemes. Browsers remove those characters before
| parsing a scheme, allowing an executable link to pass the plugin's
| check. When an application processes attacker-controlled SVG input
| and serves the result in an active browser context, a victim who
| activates the surviving link can execute script in the SVG's origin,
| expose data, modify content, or perform actions as the victim. This
| issue is fixed in versions 2.8.4, 3.3.5, and 4.1.0.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-29074
    https://www.cve.org/CVERecord?id=CVE-2026-29074
[1] https://security-tracker.debian.org/tracker/CVE-2026-73650
    https://www.cve.org/CVERecord?id=CVE-2026-73650
[2] https://security-tracker.debian.org/tracker/CVE-2026-84369
    https://www.cve.org/CVERecord?id=CVE-2026-84369
[3] https://security-tracker.debian.org/tracker/CVE-2026-84370
    https://www.cve.org/CVERecord?id=CVE-2026-84370

Regards,
Salvatore

-- 
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel

Reply via email to