Skip to content

Code injection via SVG file in convert-svg-core

High severity GitHub Reviewed Published Jun 11, 2022 to the GitHub Advisory Database • Updated Jan 27, 2023

Package

npm convert-svg-core (npm)

Affected versions

< 0.6.3

Patched versions

0.6.3

Description

The package convert-svg-core before 0.6.3 are vulnerable to Arbitrary Code Injection when using a specially crafted SVG file. An attacker can read arbitrary files from the file system and then show the file content as a converted PNG file.

References

Published by the National Vulnerability Database Jun 10, 2022
Published to the GitHub Advisory Database Jun 11, 2022
Reviewed Jun 17, 2022
Last updated Jan 27, 2023

Severity

High
8.6
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

CVE ID

CVE-2022-24429

GHSA ID

GHSA-54px-mhwv-5v8x

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.