Lucene search

K
osvGoogleOSV:GHSA-JV7G-9G6Q-CXVW
HistoryJan 27, 2022 - 2:04 p.m.

Path Traversal in convert-svg packages

2022-01-2714:04:28
Google
osv.dev
36
path traversal
convert-svg
png
jpeg
security issue
file system

EPSS

0.002

Percentile

57.9%

This affects all versions of package convert-svg-core; all versions of package convert-svg-to-png; all versions of package convert-svg-to-jpeg. Using a specially crafted SVG file, an attacker could read arbitrary files from the file system and then show the file content as a converted PNG file.

EPSS

0.002

Percentile

57.9%

Related for OSV:GHSA-JV7G-9G6Q-CXVW