Lucene search

K
osvGoogleOSV:GHSA-3VCG-8P79-JPCV
HistoryMay 06, 2021 - 6:52 p.m.

SVGlib Vulnerable to XXE Attacks

2021-05-0618:52:01
Google
osv.dev
6
svglib
xxe attacks
python package

AI Score

9.6

Confidence

High

EPSS

0.003

Percentile

68.2%

The svglib package through 0.9.3 for Python allows XXE attacks via an svg2rlg call.

AI Score

9.6

Confidence

High

EPSS

0.003

Percentile

68.2%