The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: snyk
Published: 2022-07-22T20:00:19.307936Z
Updated: 2024-09-16T20:06:21.031Z
Reserved: 2022-02-24T00:00:00
Link: CVE-2022-25759
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-07-22T20:15:09.187
Modified: 2024-11-21T06:52:57.097
Link: CVE-2022-25759
Redhat
No data.