High severity7.5GHSA Advisory· Published Jan 21, 2022· Updated Jun 17, 2026
CVE-2021-23631
CVE-2021-23631
Description
This affects all versions of package convert-svg-core; all versions of package convert-svg-to-png; all versions of package convert-svg-to-jpeg. Using a specially crafted SVG file, an attacker could read arbitrary files from the file system and then show the file content as a converted PNG file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
convert-svg-corenpm | <= 0.5.0 | — |
convert-svg-to-pngnpm | <= 0.5.0 | — |
convert-svg-to-jpegnpm | <= 0.5.0 | — |
Affected products
4- Range: <= 0.5.0
- ghsa-coords3 versions
<= 0.5.0+ 2 more
- (no CPE)range: <= 0.5.0
- (no CPE)range: <= 0.5.0
- (no CPE)range: <= 0.5.0
Patches
Vulnerability mechanics
References
6- gist.github.com/legndery/a248350bb25b8502a03c2f407cedeb14nvdExploitThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-CONVERTSVGCORE-1582785nvdExploitThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-CONVERTSVGTOJPEG-2348245nvdExploitThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-CONVERTSVGTOPNG-2348244nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-jv7g-9g6q-cxvwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-23631ghsaADVISORY
News mentions
0No linked articles in our index yet.