Critical severity9.9NVD Advisory· Published Jul 22, 2022· Updated Jun 17, 2026
CVE-2022-25759
CVE-2022-25759
Description
The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
convert-svg-corenpm | < 0.6.2 | 0.6.2 |
Affected products
2- convert-svg-core/convert-svg-coredescription
Patches
Vulnerability mechanics
References
6- github.com/neocotic/convert-svg/commit/7e6031ac7427cf82cf312cb4a25040f2e6efe7a5nvdPatchThird Party AdvisoryWEB
- github.com/neocotic/convert-svg/pull/82nvdPatchThird Party AdvisoryWEB
- github.com/neocotic/convert-svg/issues/81nvdExploitIssue TrackingThird Party AdvisoryWEB
- security.snyk.io/vuln/SNYK-JS-CONVERTSVGCORE-2849633nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-5gxc-fxcr-9326ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-25759ghsaADVISORY
News mentions
0No linked articles in our index yet.