CVE-2022-25759
critical · 9.9The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload.
9.9
CVSS
11.2%
EPSS (exploit prob.)
96th
EPSS percentile
2022-07-22
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-94
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| convert-svg-core_project | convert-svg-core | < 0.6.2 |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/neocotic/convert-svg/commit/7e6031ac7427cf82cf312cb4a25040f2e6efe7a5
- https://github.com/neocotic/convert-svg/issues/81
- https://github.com/neocotic/convert-svg/pull/82
- https://security.snyk.io/vuln/SNYK-JS-CONVERTSVGCORE-2849633
- https://github.com/neocotic/convert-svg/commit/7e6031ac7427cf82cf312cb4a25040f2e6efe7a5
- https://github.com/neocotic/convert-svg/issues/81
- https://github.com/neocotic/convert-svg/pull/82
- https://security.snyk.io/vuln/SNYK-JS-CONVERTSVGCORE-2849633
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-25759