airmrcr/convert-svg

airmrcr/convert-svg

Releases15
Frequency6 months 2 weeks
Last Release
Stars200
Node.js packages for converting SVG into other formats using headless Chromium

CVE History

CVEPublishedCVSS v3CVSS v2
9.9 CRITICAL

The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload.

7.5 HIGH6.8 MEDIUM

The package convert-svg-core before 0.6.3 are vulnerable to Arbitrary Code Injection when using a specially crafted SVG file. An attacker can read arbitrary files from the file system and then show the file content as a converted PNG file.

7.5 HIGH7.5 HIGH

The package convert-svg-core before 0.6.4 are vulnerable to Directory Traversal due to improper sanitization of SVG tags. Exploiting this vulnerability is possible by using a specially crafted SVG file.