PT-2026-71734 · Npm · Svgo

CVE-2026-73650

·

Published

2026-07-21

·

Updated

2026-09-04

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions SVGO versions 1.0.0 through 2.8.2 SVGO versions 3.0.0 through 3.3.3 SVGO versions 4.0.0 through 4.0.1
Description The removeScripts plugin (known as removeScriptElement in versions 1 through 3) fails to remove namespaced or prefixed script elements, such as <svg:script>, and performs case-sensitive matching for JavaScript URIs in versions 3 and 4. This allows executable content to remain in optimized SVG files. Applications processing untrusted SVG input with this plugin enabled may allow scripts to execute when a user opens the file, potentially exposing cookies or local storage.
Recommendations Update to version 2.8.3. Update to version 3.3.4. Update to version 4.0.2.

Exploit

Fix

XSS

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73650
GHSA-2P49-HGCM-8545
OPENSUSE-SU-2026:11680-1

Affected Products

Svgo