Lucene search

K
osvGoogleOSV:GHSA-5F47-RCG5-9M24
HistoryJun 11, 2022 - 12:00 a.m.

Directory traversal in convert-svg-core

2022-06-1100:00:18
Google
osv.dev
14
vulnerability
directory traversal
convert-svg-core
svg
software

EPSS

0.002

Percentile

56.1%

The package convert-svg-core before 0.6.4 is vulnerable to Directory Traversal due to improper sanitization of SVG tags. Exploiting this vulnerability is possible by using a specially crafted SVG file.

EPSS

0.002

Percentile

56.1%

Related for OSV:GHSA-5F47-RCG5-9M24