VDB
Sign up
HIGH7.5

GHSA-5f47-rcg5-9m24

Directory traversal in convert-svg-core

Quick fix

GHSA-5f47-rcg5-9m24 — convert-svg-core: upgrade to the fixed version with the command below.

npm install convert-svg-core@0.6.4

Details

The package convert-svg-core before 0.6.4 is vulnerable to Directory Traversal due to improper sanitization of SVG tags. Exploiting this vulnerability is possible by using a specially crafted SVG file.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/convert-svg-core
Introduced in: 0Fixed in: 0.6.4
Fixnpm install convert-svg-core@0.6.4

References