VYPR
Medium severityGHSA Advisory· Published Oct 20, 2023

svg_optimizer rubygem external XML entity (XXE) vulnerability

CVE-2023-46035

Description

An issue in Fnando svg_optimizer v.0.2.6 allows a remote attacker to escalate privileges when optimizing untrusted SVG content.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
svg_optimizerRubyGems
>= 0.2.6, < 0.3.00.3.0

Affected products

2

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.