Source: node-svgo Version: 3.3.2+ds-1 X-Debbugs-CC: [email protected] Severity: important Tags: security upstream
Hi, The following vulnerabilities were published for node-svgo. CVE-2026-29074[0]: | SVGO, short for SVG Optimizer, is a Node.js library and command-line | application for optimizing SVG files. From version 2.1.0 to before | version 2.8.1, from version 3.0.0 to before version 3.3.3, and | before version 4.0.1, SVGO accepts XML with custom entities, without | guards against entity expansion or recursion. This can result in a | small XML file (811 bytes) stalling the application and even | crashing the Node.js process with JavaScript heap out of memory. | This issue has been patched in versions 2.8.1, 3.3.3, and 4.0.1. CVE-2026-73650[1]: | SVGO, short for SVG Optimizer, is a Node.js library and command-line | application for optimizing SVG files. From version 1.0.0 until | versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named | removeScriptElement in versions 1 through 3, can leave executable | content in optimized SVGs because it does not remove namespaced or | prefixed script elements such as <svg:script> and, in versions 3 and | 4, matches JavaScript URIs case sensitively. Applications that | process untrusted SVG input with this plugin enabled and serve the | result can allow scripts to execute when another user opens the SVG, | exposing local storage or cookies. This issue is fixed in versions | 2.8.3, 3.3.4, and 4.0.2. CVE-2026-84369[2]: | SVGO, short for SVG Optimizer, is a Node.js library and command-line | application for optimizing SVG files. From version 1.0.0 until | versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, | named removeScriptElement in versions 2 and 3 and implemented in | plugins/removeScripts.js, removes SVG and XHTML script elements but | does not inspect executable HTML content inside SVG foreignObject | elements. Event-handler attributes such as onload and | onbeforetoggle, srcdoc documents, and executable URLs in the action, | data, formaction, href, and src attributes can remain in attacker- | controlled SVG input. When an application uses the plugin as its | only protection and serves the optimized SVG in an active browser | context, the payload can execute script in the viewer's origin, | expose data, modify content, or perform actions as the victim. This | issue is fixed in versions 2.8.4, 3.3.5, and 4.1.0. CVE-2026-84370[3]: | SVGO, short for SVG Optimizer, is a Node.js library and command-line | application for optimizing SVG files. From version 1.0.0 until | versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, | named removeScriptElement in versions 2 and 3, incompletely filters | executable links in plugins/removeScripts.js and lib/svgo/tools.js. | The plugin does not recognize namespace-prefixed SVG anchor elements | such as svg:a with href or namespaced *:href values, and it does not | remove ASCII tab, line-feed, or carriage-return characters before | checking URL schemes. Browsers remove those characters before | parsing a scheme, allowing an executable link to pass the plugin's | check. When an application processes attacker-controlled SVG input | and serves the result in an active browser context, a victim who | activates the surviving link can execute script in the SVG's origin, | expose data, modify content, or perform actions as the victim. This | issue is fixed in versions 2.8.4, 3.3.5, and 4.1.0. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-29074 https://www.cve.org/CVERecord?id=CVE-2026-29074 [1] https://security-tracker.debian.org/tracker/CVE-2026-73650 https://www.cve.org/CVERecord?id=CVE-2026-73650 [2] https://security-tracker.debian.org/tracker/CVE-2026-84369 https://www.cve.org/CVERecord?id=CVE-2026-84369 [3] https://security-tracker.debian.org/tracker/CVE-2026-84370 https://www.cve.org/CVERecord?id=CVE-2026-84370 Regards, Salvatore -- Pkg-javascript-devel mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel
