← Back to browse · API

CVE-2022-25759

Severity
CRITICAL
CVSS
9.9
EPSS
0.10997
Risk score
43.45
CISA KEV
No
PoC
No
Published
2022-07-22
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2022-6244, GHSA-5GXC-FXCR-9326
Products
n/a:convert-svg-core unspecified <0.6.2
Sources
euvd EUVD-2022-6244

Description

The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload.

References