npm package
convert-svg-core
pkg:npm/convert-svg-core
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-25759 | — | < 0.6.2 | 0.6.2 | Jul 22, 2022 | The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload. | ||
| CVE-2022-24278 | — | < 0.6.4 | 0.6.4 | Jun 10, 2022 | The package convert-svg-core before 0.6.4 are vulnerable to Directory Traversal due to improper sanitization of SVG tags. Exploiting this vulnerability is possible by using a specially crafted SVG file. | ||
| CVE-2022-24429 | — | < 0.6.3 | 0.6.3 | Jun 10, 2022 | The package convert-svg-core before 0.6.3 are vulnerable to Arbitrary Code Injection when using a specially crafted SVG file. An attacker can read arbitrary files from the file system and then show the file content as a converted PNG file. | ||
| CVE-2021-23631 | — | <= 0.5.0 | — | Jan 21, 2022 | This affects all versions of package convert-svg-core; all versions of package convert-svg-to-png; all versions of package convert-svg-to-jpeg. Using a specially crafted SVG file, an attacker could read arbitrary files from the file system and then show the file content as a conv |
- CVE-2022-25759Jul 22, 2022affected < 0.6.2fixed 0.6.2
The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload.
- CVE-2022-24278Jun 10, 2022affected < 0.6.4fixed 0.6.4
The package convert-svg-core before 0.6.4 are vulnerable to Directory Traversal due to improper sanitization of SVG tags. Exploiting this vulnerability is possible by using a specially crafted SVG file.
- CVE-2022-24429Jun 10, 2022affected < 0.6.3fixed 0.6.3
The package convert-svg-core before 0.6.3 are vulnerable to Arbitrary Code Injection when using a specially crafted SVG file. An attacker can read arbitrary files from the file system and then show the file content as a converted PNG file.
- CVE-2021-23631Jan 21, 2022affected <= 0.5.0
This affects all versions of package convert-svg-core; all versions of package convert-svg-to-png; all versions of package convert-svg-to-jpeg. Using a specially crafted SVG file, an attacker could read arbitrary files from the file system and then show the file content as a conv