High severity7.6NVD Advisory· Published Mar 1, 2022· Updated Jun 17, 2026
CVE-2022-24718
CVE-2022-24718
Description
ssr-pages is an HTML page builder for the purpose of server-side rendering (SSR). In versions prior to 0.1.4, a path traversal issue can occur when providing untrusted input to the svg property as an argument to the build(MessagePageOptions) function. While there is no known workaround at this time, there is a patch in version 0.1.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@finastra/ssr-pagesnpm | < 0.1.4 | 0.1.4 |
Affected products
2Patches
Vulnerability mechanics
References
5- github.com/Finastra/ssr-pages/pull/1nvdPatchThird Party AdvisoryWEB
- github.com/Finastra/ssr-pages/pull/1/commits/c3e4c563384ae3ba3892f37dd190218577620780nvdPatchThird Party AdvisoryWEB
- github.com/Finastra/ssr-pages/security/advisories/GHSA-w6cx-qg2q-rvq8nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-w6cx-qg2q-rvq8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-24718ghsaADVISORY
News mentions
0No linked articles in our index yet.