VDB
Sign up
HIGH8.6

GHSA-54px-mhwv-5v8x

Code injection via SVG file in convert-svg-core

Quick fix

GHSA-54px-mhwv-5v8x — convert-svg-core: upgrade to the fixed version with the command below.

npm install convert-svg-core@0.6.3

Details

The package convert-svg-core before 0.6.3 are vulnerable to Arbitrary Code Injection when using a specially crafted SVG file. An attacker can read arbitrary files from the file system and then show the file content as a converted PNG file.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/convert-svg-core
Introduced in: 0Fixed in: 0.6.3
Fixnpm install convert-svg-core@0.6.3

References