← Back to browse · API

CVE-2020-7750

Severity
CRITICAL
CVSS
9.6
EPSS
0.06148
Risk score
40.55
CISA KEV
No
PoC
No
Published
2020-10-21
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2020-1459, GHSA-J977-G5VJ-J27G
Products
n/a:scratch-svg-renderer unspecified <0.2.0-prerelease.20201019174008
Sources
euvd EUVD-2020-1459

Description

This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not escape SVG properly, which can be used to inject arbitrary elements into the DOM via the _transformMeasurements function.

References